Will we see other OAuth providers follow suit and start randomizing email addresses and user IDs returned to apps? I hope so!
Ironically, Facebook first started doing this a few years ago when they launched app-scoped user IDs.
3
1
1
3
Anyway, if you're curious about what this will look like, I wrote a sample app that uses Sign In with Apple so you can see how it works.
developer.okta.com/blog/2019…
3
3
2
25
Now I would just love to have a quick guide for using Apple Sign In as an Okta generic oidc inbound provider. Is this possible already ?
1
Do you know where you can find the .well-known/openid-configuration on the apple url?
Do they even use it?
1
So talked with the Apple engineers here at WWDC:
They don't have that endpoint, they also will not expose user_info or a revocation endpoint. The user_info will only be sent once and only once then you will only get a unique id again. Only scopes available now are name and email
3
Another question, if there is no `user_info` endpoint, what are the access token and refresh tokens for?
1
verify where? The unique ID comes back in the ID token not the access token. (also happy to take this to DM)
Jun 6, 2019 · 11:20 PM UTC


