ID Token And Access Token

What Is an ID Token?

ID Token Scenario
"iss": "",
"sub": "auth0|123456",
"aud": "1234abcdef",
"exp": 1311281970,
"iat": 1311280970,
"name": "Jane Doe",
"given_name": "Jane",
"family_name": "Doe"

Actually, the OpenID Connect specifications don’t require the ID token to have user’s claims. In its minimal structure, it has no data about the user; just info about the authentication operation.

Remember this small detail about the audience claim because it will help you better understand what its correct use is later on.

What Is an Access Token ?

Access Token Scenario

What Is an ID Token NOT Suitable For?

What Is an Access Token NOT Suitable For?



