Now I would just love to have a quick guide for using Apple Sign In as an Okta generic oidc inbound provider. Is this possible already ?
1
Do you know where you can find the .well-known/openid-configuration on the apple url?
Do they even use it?
1
So talked with the Apple engineers here at WWDC:
They don't have that endpoint, they also will not expose user_info or a revocation endpoint. The user_info will only be sent once and only once then you will only get a unique id again. Only scopes available now are name and email
3
Just verified again, and I don't get back name or email address when I request "name email" scope.
I did find a bug where apparently Apple is ignoring the "scope" parameter after the very first time you authorize an app though, so could be related.
1
That is not a bug that is feature. They told me they will only give you the info once. Probably why scope won’t matter after your first invoke.
2
interesting. well the bug is that I have *never* gotten it, because I didn't request it the first time, and now I can't request it ever again.
1
Progress! I now get the screen which lets me edit my name and choose the email to share. I only see that the first time, all subsequent requests show a confirmation only.
Still no luck actually getting the email address back in the ID token though.
Jun 6, 2019 · 11:07 PM UTC
1


