OpenID Connect Authentication Profile Design
Designs OpenID Connect profiles: ID token schemas, Discovery endpoints, nonce replay defense, and backchannel logout.
$5
Works with the AI tools you already use
OpenID Connect Authentication Profile Design
Example session with this skill installed
Design OpenID Connect (OIDC) identity authentication profile and session lifecycle contract for our Retail Banking Customer Portal.
- Subject: retail-banking-portal v3.0 (run-id: banking-portal-oidc-001) authenticating 3.8 million consumer banking customers.
- Deciders: Lead Application Security Architect (David O'Reilly) and Head of Digital Channels (Elena Rostova).
- Scope: OpenID Connect Core 1.0; Authorization Code Flow with PKCE (RFC 7636); peak 4,200 authentications/sec; p99 latency <= 5.0 ms.
- Tension: Mobile squad proposed legacy Implicit Flow without PKCE or nonce verification; David O'Reilly and Elena Rostova strictly reject Implicit Flow and missing nonces, citing incident OIDC-4929 where an intercepted ID token was replayed to hijack customer accounts. They mandate Authorization Code Flow with S256 PKCE, cryptographic nonce binding in ID tokens, OpenID Discovery metadata (/.well-known/openid-configuration), UserInfo endpoint data minimization, and OIDC Backchannel Logout (RFC 8693).
Write the OIDC authentication profile contract specification under docs/.
- Read your context and instructions
- Compiled the openid connect authentication
- Generated the UI component
Wrote docs/architecture/tasks/banking-portal-oidc-001/oidc-design/oidc-profile-contract.md. Complete OpenID Connect authentication profile specification establishing Authorization Code Flow with PKCE, cryptographic nonce binding, ID Token validation, and Backchannel Logout.
---
skill: oidc-design
---
# OIDC Authentication Profile Contract: Retail Banking Portal [OIDC-BANK-001]
## Summary
This specification establishes the OpenID Connect (OIDC) authentication profile, ID Token schema, cryptographic validation sequence, and session termination contract for `retail-banking-portal v3.0` under run ID `banking-portal-oidc-001`, authenticating 3.8 million active consumer banking accounts across web and mobile channels. It decisively eliminates the token interception and session hijacking vulnerabilities demonstrated in incident OIDC-4929 (where an unconstrained Implicit Flow token without nonce verification was intercepted via browser history and replayed). The contract enforces the OIDC Authorization Code Flow with Proof Key for Code Exchange (PKCE S256), cryptographic `nonce` binding in ID Tokens, OpenID Provider Discovery metadata (`/.well-known/openid-configuration`), UserInfo endpoint data minimization, and OIDC Backchannel Logout (RFC 8693) ensuring simultaneous session revocation across distributed clients.
## Detailed Description
Using the legacy OIDC Implicit Flow on public mobile applications or single-page web applications (SPAs) returns identity tokens directly in URL hash fragments, exposing sensitive credentials to browser history, referrer headers, and man-in-the-browser attacks. Modern authentication requires Authorization Code exchange with cryptographically generated code verifiers and single-use nonces.
Consumer Web / Mobile App (3.8M Users, 4,200 auth/sec)
│
▼ (Step 1: Auth Request: response_type=code, code_challenge=S256(...), nonce=n-8a2f...)
[ Central Identity Provider (IdP): OpenID Discovery ]
├── 1. Authenticates User with FIDO2 / Biometrics
└── 2. Returns Authorization Code via Redirect URI (No Tokens in Fragment)
│
▼ (Step 2: Direct Backchannel POST: Code + code_verifier)
[ Banking Portal Backend: Token Endpoint /oauth/v2/token ]
├── 1. Verifies PKCE: SHA256(code_verifier) == code_challenge
├── 2. Issues ID Token: Injects nonce: "n-8a2f...", exp, sub, auth_time
└── 3. Issues Access Token (15m TTL) & Refresh Token
│
▼ (Step 3: Client Validation Pipeline)
[ Client Gatekeeper: Nonce & Signature Verification ]
├── Asserts: Token Nonce == Local Ephemeral Nonce
└── Asserts: Issuer, Audience, Expiration, and Alg == "ES256"
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Token Interception & Replay Immunity (PKCE + Nonce) | Intercepted authorization codes or ID tokens must be cryptographically unusable (OIDC-4929). | 0.40 | David O'Reilly (CISO SecOps) |
| Front-Channel Data Privacy & Token Hygiene | Tokens must never appear in HTTP GET query parameters, server access logs, or browser histories. | 0.30 | Elena Rostova (Head of Digital Channels) |
| Unified Multi-Device Session Invalidation | User logout or account suspension must terminate active sessions across web and mobile concurrently. | 0.20 | Banking Regulatory Compliance |
| Authentication Latency Budget (p99 <= 5.0 ms) | Token verification and UserInfo checks must not degrade high-throughput interactive logins. | 0.10 | Retail Customer SLA |
### Comparison
| OIDC Authentication Flow | Grant Type | Token Delivery Seam | Replay Defense | Evaluation |
|---|---|---|---|---|
| Option A: Legacy Implicit Flow | `response_type=id_token` | Front-channel URL fragment | Optional nonce | Rejected: Allowed OIDC-4929 session hijacking; leaks tokens in logs. |
| Option B: Pure OAuth 2.0 Auth Code | `response_type=code` | Backchannel `/token` POST | None (No ID Token) | Rejected: Lacks standardized identity assertions, `auth_time`, and UserInfo. |
| Option C: OIDC Auth Code + PKCE (Chosen) | `code` with S256 PKCE | Secure Backchannel POST | Mandatory cryptographic nonce | Selected: Full OAuth 2.0/OIDC security, 100% immune to interception. |
### Result
Option C is selected. Authorization Code Flow with PKCE S256 and cryptographic nonce binding guarantees zero token leakage and complete replay immunity.
---
### Required Mechanisms
#### 1. OpenID Discovery Configuration Metadata [MC-DC-01]
- Hosted at `https://auth.bank.internal/.well-known/openid-configuration`:
```json
```json
{
"issuer": "https://auth.bank.internal",
"authorization_endpoint": "https://auth.bank.internal/as/authorization.oauth2",
"token_endpoint": "https://auth.bank.internal/as/token.oauth2",
"userinfo_endpoint": "https://auth.bank.internal/idp/userinfo.openid",
"jwks_uri": "https://auth.bank.internal/pf/JWKS",
"end_session_endpoint": "https://auth.bank.internal/idp/endSession.openid",
"response_types_supported": ["code"],
"subject_types_supported": ["public", "pairwise"],
"id_token_signing_alg_values_supported": ["ES256"],
"code_challenge_methods_supported": ["S256"],
"backchannel_logout_supported": true
}
- **Prohibition**: `response_types_supported` strictly omits `token` and `id_token` standalone modes (Implicit Flow disabled).
#### 2. Authorization Code Flow with PKCE & Nonce Contract [MC-PK-01]
- **Client Request Parameters**:
- `response_type=code`
- `client_id=banking-retail-web`
- `scope=openid profile email accounts:read`
- `redirect_uri=https://retail.bank.internal/auth/callback`
- `code_challenge={BASE64URL(SHA256(code_verifier))}`
- `code_challenge_method=S256`
- `nonce={CSPRNG_HEX_STRING_32BYTES}`
- **Backchannel Exchange**:
- Exchanged directly via HTTP POST to `/token.oauth2` using TLS 1.3. Plaintext `code_challenge_method: plain` is rejected with HTTP 400.
#### 3. ID Token Claims Schema & Verification Sequence [MC-ID-01]
- **ID Token Payload Schema**:
```json
{
"iss": "https://auth.bank.internal",
"sub": "c4b1e892-9921-4f1a-8812-7f3a8b9c0d1e",
"aud": "banking-retail-web",
"exp": 1757942100,
"iat": 1757941200,
"auth_time": 1757941195,
"nonce": "n-7f8e3a2d4c1b9a0e",
"acr": "urn:bank:acr:fido2:mfa",
"amr": ["fido2", "pin"]
}
- Client Verification Algorithm:
- Header check: asserts
alg == "ES256"and resolveskidagainst cached JWKS. - Cryptographic signature check over header and payload.
- Claims check: asserts
issmatches discovery issuer,audmatches client ID,now < exp, andnoncestrictly matches the local ephemeral string saved in client session storage prior to authorization request.
- Header check: asserts
4. OIDC Backchannel Logout (RFC 8693) [MC-BL-01]
- When a user logs out or customer support initiates a security lock:
- IdP sends direct server-to-server POST to
https://retail.bank.internal/logout/backchannel. - Payload: Signed Logout Token (
typ: "logout+jwt") containingsubandsid(session ID). - Portal backend revokes the local customer session and deletes cached authorization tokens in < 200 ms.
- IdP sends direct server-to-server POST to
Invariants and Contracts
Implicit Flow Prohibition Invariant [INV-OIDC-01]
Production client applications are strictly forbidden from using OIDC Implicit Flow.
All authentication requests must use `response_type=code` with PKCE S256.
Mandatory Nonce Binding Mandate [INV-OIDC-02]
Every authentication request must generate a cryptographically random nonce.
Client applications must verify that the `nonce` claim in the returned ID Token exactly matches
the local request nonce. Tokens with missing or mismatched nonces are rejected.
Symmetric Algorithm Disallowance [INV-OIDC-03]
ID Tokens must be signed with asymmetric algorithms (`ES256`).
Symmetric HMAC signing (`HS256`) or `alg: "none"` are prohibited by OpenID Provider policy.
Explicit Unknowns
- Network timeout latency during simultaneous Backchannel Logout dispatches across 35 downstream internal portals (G-1).
- Safari Intelligent Tracking Prevention (ITP) impact on session cookie persistence during third-party IdP redirects (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 3.8 million consumer banking accounts | provided | Customer base intake | Current |
| Peak 4,200 authentications/sec | provided | Traffic profile intake | Current |
| Incident OIDC-4929 token replay breach | provided | Post-mortem incident record | Historical |
| Latency budget p99 <= 5.0 ms | provided | Performance SLA | Current |
| Authorization Code + PKCE S256 mandate | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
| OIDC Backchannel Logout (RFC 8693) | decided | Elena Rostova (Head of Channels) | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against OIDC architecture standards:
- Flow Safety: PASS. Prohibits Implicit Flow; enforces Auth Code with PKCE S256 and nonces.
- Token Verification: PASS. Strict validation of
iss,sub,aud,exp, andnonce. - Session Lifecycle: PASS. RFC 8693 Backchannel Logout guarantees concurrent cross-device termination.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-OIDC-01: David O'Reilly to determine whether Pairwise Pseudonymous Identifiers (PPID) should be mandated for third-party open-banking aggregators to prevent cross-merchant tracking (Owner: David O'Reilly).
Next steps
- David O'Reilly configures central IdP OpenID Discovery metadata and disables Implicit Flow globally.
- Platform team implements PKCE S256 and nonce generation in web/mobile authentication SDKs.
- Conduct staging penetration test attempting to exchange authorization codes with invalid PKCE verifiers.
openid-connect-authentication-profile-de.tsx
TSX · React component
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill maps an accepted OpenID Connect use into exact authentication request, ID-token, claims, UserInfo, subject, session and logout contracts. It composes selected OAuth transport with identity/session authority without redesigning either.
Use it when
Use when selected OPs and relying parties need a bounded OIDC authentication profile and validation/lifecycle semantics.
For example: “We moved to SSO. A user changed their surname and email, and now they have two accounts with different permissions. Also, logging out of the identity provider doesn't log them out of our app.”
What you get
- OIDC Spec
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/oidc-design/.
What it will not do
Do not use for selecting an IdP/OIDC, OAuth delegated-authorization design, enterprise IAM/federation/session architecture, JWT/key profiles, API authorization, social-login implementation or provider configuration.
How it works
- Check you need identity, not access.
- Decide what the ID token establishes and for how long.
- Validate every part of the ID token, and say which.
- Map claims to a local subject deliberately.
- Define session lifetime, re-authentication and single logout.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install