Skip to main content

SID-AUTH-03 — OIDC Gate for External Identity Providers

PropertyValue
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupAuthentication Controls

Description

External OIDC ID tokens validated for gated registration/login flows. Validates issuer, audience, JWT signature via JWKS discovery, expiration with configurable clock skew. Caches validators per provider.

Components

Source References

Framework Requirements

ISO 27001 Annex A: A.5.16, A.8.5

OWASP ASVS 4.0.3 Level 3: V1.2, V3.6