<div dir="ltr">Sunil - <div><br></div><div> I have not reviewed what Claude has (or has not) done with the instructions, but the official installation instructions can be found at <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP</a></div><div><br></div><div><div> The official project documentation is probably a better source than an AI summary (or echo).</div></div><div><br></div><div> I will also note that IDP 5.1.4 is not the current release, you should consider upgrading to 5.2.1.</div><div><br></div><div>Steve.</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Sat, Apr 4, 2026 at 1:03 PM Mathew, Sunil via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black">Hi,</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black">I am enabling OIDC in our Shibboleth IdP 5.1.4. Claude gave me these as the steps. Can you please confirm this looks correct?</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
Appreciate your help.</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black">Regards,</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black">Sunil</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div style="direction:ltr;font-family:Aptos;font-size:12pt;color:black"><br>
</div>
<div id="m_-2748430343104530517mail-editor-reference-message-container">
<h3 style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif">Part 1: Shibboleth IdP Side</span></h3>
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">1. Install the OIDC OP Plugin</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">The OIDC OP plugin is an officially supported plugin for Shibboleth IdP v4.1 and above. It must be installed using the
<code>plugin</code> command: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
bash</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt;color:rgb(20,24,31)"><code>/opt/shibboleth-idp/bin/plugin.sh -I net.shibboleth.idp.plugin.oidc.op</code></div></pre>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">This plugin depends on the Shibboleth OIDC Common plugin (<code>OIDCCommon</code>) and
<code>OIDCConfig</code> (since v3.4.0), which must be installed first. <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">2. Enable the OIDC Module</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Once the plugin has been installed, verify or enable the module:
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
bash</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt;color:rgb(20,24,31)"><code>/opt/shibboleth-idp/bin/module.sh -e idp.oidc.OP</code></div></pre>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">3. Initial Configuration Files (<code>conf/credentials.xml</code>)</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Add an import for OIDC credentials into
<code>conf/credentials.xml</code>: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
xml</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(110,118,135)"><code><!-- OIDC extension default credential definitions --></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>import </code></span><span style="color:rgb(189,15,30)"><code>resource</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>oidc-credentials.xml</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(43,48,59)"><code>/></code></span></div></pre>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Also enable auto-loading of properties by setting in
<code>idp.properties</code>:</span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
properties</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(189,15,30)"><code>idp.searchForProperties</code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(0,128,0)"><code>true</code></span></div></pre>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">4. Generate Signing & Encryption Keys</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">The default configuration expects two RSA keys (one for signing, one for decryption) and one EC key. Generate them using the provided
<code>jwtgen</code> utility: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
bash</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(179,74,0)"><code>cd</code></span><span style="color:rgb(20,24,31)"><code> /opt/shibboleth-idp
bin/jwtgen.sh -t RSA -s </code></span><span style="color:rgb(0,128,128)"><code>2048</code></span><span style="color:rgb(20,24,31)"><code> -u sig -i defaultRSASign | </code></span><span style="color:rgb(0,81,194)"><code>tail</code></span><span style="color:rgb(20,24,31)"><code> -n +2 > credentials/idp-signing-rs.jwk
bin/jwtgen.sh -t EC -c P-256 -u sig -i defaultECSign | </code></span><span style="color:rgb(0,81,194)"><code>tail</code></span><span style="color:rgb(20,24,31)"><code> -n +2 > credentials/idp-signing-es.jwk
bin/jwtgen.sh -t RSA -s </code></span><span style="color:rgb(0,128,128)"><code>2048</code></span><span style="color:rgb(20,24,31)"><code> -u enc -i defaultRSAEnc | </code></span><span style="color:rgb(0,81,194)"><code>tail</code></span><span style="color:rgb(20,24,31)"><code> -n +2 > credentials/idp-encryption-rsa.jwk</code></span></div></pre>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">5. Set the OIDC Issuer (<code>conf/oidc.properties</code>)</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">The issuer must be a URL using the
<code>https</code> scheme containing a host and optionally port/path, with no query or fragment components:
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
properties</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(189,15,30)"><code>idp.oidc.issuer</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code><a href="https://your-idp.example.org" target="_blank">https://your-idp.example.org</a></code></span></div></pre>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">6. Expose the OpenID Discovery Document</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Clients (like GraphDB) use the
<code>/.well-known/openid-configuration</code> endpoint to auto-configure themselves. You must either publish the static file at the standard path or route
<code><a href="https://your-idp.example.org/.well-known/openid-configuration" target="_blank">https://your-idp.example.org/.well-known/openid-configuration</a></code> to <code>
/idp/profile/oidc/configuration</code>. <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Update the template at
<code>static/openid-configuration.json</code> by replacing <code>{{ service_name }}</code> with the host portion of your issuer.</span></p>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">7. Enable OIDC Profiles in
<code>conf/relying-party.xml</code></span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">The keyset profile must be openly accessible, and the functional profiles (SSO, UserInfo, Token, etc.) should be enabled under the default relying party:
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
xml</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>bean </code></span><span style="color:rgb(189,15,30)"><code>id</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>shibboleth.UnverifiedRelyingParty</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(189,15,30)"><code>parent</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>RelyingParty</code></span><span style="color:rgb(43,48,59)"><code>"></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>property </code></span><span style="color:rgb(189,15,30)"><code>name</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>profileConfigurations</code></span><span style="color:rgb(43,48,59)"><code>"></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>list</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OIDC.Keyset</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(43,48,59)"><code>/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>list</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>property</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>bean </code></span><span style="color:rgb(189,15,30)"><code>id</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>shibboleth.DefaultRelyingParty</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(189,15,30)"><code>parent</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>RelyingParty</code></span><span style="color:rgb(43,48,59)"><code>"></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>property </code></span><span style="color:rgb(189,15,30)"><code>name</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>profileConfigurations</code></span><span style="color:rgb(43,48,59)"><code>"></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>list</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OIDC.SSO</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(43,48,59)"><code>/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OIDC.UserInfo</code></span><span style="color:rgb(43,48,59)"><code>"/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OAUTH2.Token</code></span><span style="color:rgb(43,48,59)"><code>"/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OAUTH2.Revocation</code></span><span style="color:rgb(43,48,59)"><code>"/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>ref </code></span><span style="color:rgb(189,15,30)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>OAUTH2.Introspection</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(43,48,59)"><code>/></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>list</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>property</code></span><span style="color:rgb(43,48,59)"><code>></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code></</code></span><span style="color:rgb(184,10,24)"><code>bean</code></span><span style="color:rgb(43,48,59)"><code>></code></span></div></pre>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">8. Register GraphDB as an OIDC Client (<code>metadata/oidc-client.json</code>)</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">For static client registration, create or edit
<code>metadata/oidc-client.json</code> to register GraphDB as a relying party: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
json</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(43,48,59)"><code>[</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code>{</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"scope"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(0,128,0)"><code>"openid email"</code></span><span style="color:rgb(43,48,59)"><code>,</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"redirect_uris"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(43,48,59)"><code>[</code></span><span style="color:rgb(0,128,0)"><code>"<a href="https://graphdb.example.org:7200/" target="_blank">https://graphdb.example.org:7200/</a>"</code></span><span style="color:rgb(43,48,59)"><code>],</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"client_id"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(0,128,0)"><code>"graphdb-client"</code></span><span style="color:rgb(43,48,59)"><code>,</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"client_secret"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(0,128,0)"><code>"your-secret-here"</code></span><span style="color:rgb(43,48,59)"><code>,</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"response_types"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(43,48,59)"><code>[</code></span><span style="color:rgb(0,128,0)"><code>"code"</code></span><span style="color:rgb(43,48,59)"><code>],</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(184,10,24)"><code>"grant_types"</code></span><span style="color:rgb(20,24,31)"><code>: </code></span><span style="color:rgb(43,48,59)"><code>[</code></span><span style="color:rgb(0,128,0)"><code>"authorization_code"</code></span><span style="color:rgb(43,48,59)"><code>]</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code>}</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(43,48,59)"><code>]</code></span></div></pre>
<blockquote>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)"><b>Note:</b> The GraphDB Workbench uses its own root browser URL (e.g.,
<code><a href="https://graphdb.example.com:7200/" target="_blank">https://graphdb.example.com:7200/</a></code> with a trailing slash) as the <code>
redirect_uri</code> when redirecting to the authorization endpoint. This value must be registered with the OpenID provider.
<a href="https://graphdb.ontotext.com/documentation/11.3/access-control.html#access-control-openid-authentication" style="margin-top:0px;margin-bottom:0px" target="_blank">
ontotext</a></span></p>
</blockquote>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Enable the file resolver in
<code>conf/oidc-clientinfo-resolvers.xml</code> by uncommenting the <code>ExampleFileResolver</code> bean.
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<hr style="text-align:left;text-indent:0px">
<h4 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt">9. Configure Claim/Attribute Release</span></h4>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">You can add the default OIDC claim mapping rules to
<code>conf/attributes/default-rules.xml</code> to simplify attribute-to-claim mapping:
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP" style="margin-top:0px;margin-bottom:0px" target="_blank">
Atlassian</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
xml</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(43,48,59)"><code><</code></span><span style="color:rgb(184,10,24)"><code>import </code></span><span style="color:rgb(189,15,30)"><code>resource</code></span><span style="color:rgb(43,48,59)"><code>="</code></span><span style="color:rgb(0,128,0)"><code>oidc-claim-rules.xml</code></span><span style="color:rgb(43,48,59)"><code>"</code></span><span style="color:rgb(184,10,24)"><code> </code></span><span style="color:rgb(43,48,59)"><code>/></code></span></div></pre>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">GraphDB requires a claim to use as the username (e.g.,
<code>email</code> or <code>sub</code>). Ensure the attribute filter releases this claim to GraphDB's
<code>client_id</code>. You will also need to configure the <code>sub</code> claim, as it is required by the OIDC specification.</span></p>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">If using
<b>OAuth authorization</b> (roles from JWT), also configure a <code>roles</code> claim in your attribute resolver and filter to release GraphDB roles (e.g.,
<code>ROLE_USER</code>, <code>ROLE_ADMIN</code>, <code>READ_REPO_*</code>, <code>
WRITE_REPO_*</code>) to the access token.</span></p>
<hr style="text-align:left;text-indent:0px">
<h3 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif">Part 2: GraphDB Side (<code>graphdb.properties</code>)</span></h3>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">On the GraphDB side, enable OpenID authentication and point it at the Shibboleth IdP. The issuer URL is used to derive keys, endpoints, and token validation:
<a href="https://graphdb.ontotext.com/documentation/11.3/access-control.html#access-control-openid-authentication" style="margin-top:0px;margin-bottom:0px" target="_blank">
ontotext</a></span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
properties</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(110,118,135)"><code># Enable OpenID authentication</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.methods</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>openid</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(110,118,135)"><code># Shibboleth IdP issuer URL</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.openid.issuer</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code><a href="https://your-idp.example.org" target="_blank">https://your-idp.example.org</a></code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(110,118,135)"><code># Client ID registered with Shibboleth</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.openid.client_id</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>graphdb-client</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(110,118,135)"><code># Use 'email' or whatever claim Shibboleth releases as the username</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.openid.username_claim</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>email</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(110,118,135)"><code># Use authorization code flow with PKCE (recommended)</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.openid.auth_flow</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>code</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(110,118,135)"><code># Use 'access' if the access token is a JWT, otherwise 'id'</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.openid.token_type</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>access</code></span></div></pre>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">If using OAuth (roles from JWT claims):</span></p>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<button type="button">
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
<div style="direction:ltr;text-align:left;text-indent:0px;text-transform:none">
</div>
</button></div>
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
properties</div>
<pre><div style="text-align:left;text-indent:0px;text-transform:none;font-size:12pt"><span style="color:rgb(189,15,30)"><code>graphdb.auth.database</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>oauth</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.oauth.roles_claim</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>roles</code></span><span style="color:rgb(20,24,31)"><code>
</code></span><span style="color:rgb(189,15,30)"><code>graphdb.auth.oauth.default_roles</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(43,48,59)"><code>=</code></span><span style="color:rgb(20,24,31)"><code> </code></span><span style="color:rgb(0,128,0)"><code>ROLE_USER</code></span></div></pre>
<p style="text-align:left;text-indent:0px;text-transform:none">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">The
<code>graphdb.auth.openid.token_type</code> should be set to <code>access</code> if the access token is a JWT, otherwise use
<code>id</code>. For Shibboleth with the OIDC OP plugin, the access token is typically a JWT (per RFC 9068 support), so
<code>access</code> is usually the right choice. <a href="https://graphdb.ontotext.com/documentation/11.3/access-control.html#access-control-openid-authentication" style="margin-top:0px;margin-bottom:0px" target="_blank">
ontotext</a></span></p>
<hr style="text-align:left;text-indent:0px">
<h3 style="text-align:left;text-indent:0px;text-transform:none;color:rgb(0,0,0)">
<span style="font-family:Aptos,Arial,Helvetica,sans-serif">Summary Checklist</span></h3>
<table style="text-align:left;text-indent:0px;text-transform:none">
<tbody>
<tr>
<th style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Step</div>
</th>
<th style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Where</div>
</th>
<th style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Action</div>
</th>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Install OIDC OP plugin</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Shibboleth</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>plugin.sh -I net.shibboleth.idp.plugin.oidc.op</code></div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Import <code>oidc-credentials.xml</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>conf/credentials.xml</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Add import statement</div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Generate JWK keys</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>credentials/</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Run <code>jwtgen.sh</code></div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Set issuer URL</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>conf/oidc.properties</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>idp.oidc.issuer</code></div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Expose discovery endpoint</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Web server / IdP</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Route <code>/.well-known/openid-configuration</code></div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Enable OIDC profiles</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>conf/relying-party.xml</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Add <code>OIDC.SSO</code>, <code>OIDC.UserInfo</code>, etc.</div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Register GraphDB client</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>metadata/oidc-client.json</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>client_id</code>, <code>redirect_uri</code>, scopes</div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Release username + roles claims</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Attribute filter</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Target GraphDB's <code>client_id</code></div>
</td>
</tr>
<tr>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Configure GraphDB</div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<code>graphdb.properties</code></div>
</td>
<td style="text-align:left;text-indent:0px;text-transform:none">
<div style="text-align:left;text-indent:0px;text-transform:none;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Set <code>issuer</code>, <code>client_id</code>, <code>auth_flow</code>, <code>token_type</code></div>
</td>
</tr>
</tbody>
</table>
<div style="direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>