Our IdP supports OpenID Connect Core 1.0.

For a general understanding of the OpenID Connect protocol, we recommend reading the OpenID Connect specification.

To connect an OpenID Connect RP, we require the following information from you:

  • Redirect URIs
  • TU ID of a contact person
  • Possibly functional contact address
  • Attributes to be released

Further information about the OpenID Connect RP can be provided optionally. The Shibboleth documentation specifies which of these parameters are supported by Shibboleth. The OpenID Connect Dynamic Client Registration Standard provides information on the exact meaning of the parameters.

The metadata required from the OpenID Connect provider (IdP) for a connection via OpenID Connect can be obtained directly from the IdP of the corresponding environment.

We would appreciate feedback on successful connections and configuration examples.