openid / openid/connect

Proposal: Introduction of “Light/Pure” Variants for Implicit and Hybrid Plans

Open
#2,127 6 comments 0 reactions 1 assignee View on GitHub

@fkj is already working on this.

Since Aug 27, 2026.

component: Core migrated-from-bitbucket priority: major type: proposal
Dominant language
No language data
Stars
3
Forks
3
Avg merge
20h 14m
Merged PRs (30d)
1

Description

Originally submitted by panva (Filip Skokan) on 2024-09-26

I propose an evolution of the OpenID Connect Core 1.0 certification plans: to introduce “light” or “pure” variants of the Implicit and Hybrid Core certification plans. These new plans would specifically exclude response types that issue access tokens in the front channel, to allow certification of software that only implements code, code id_token and id_token.

The reasoning is simple, I cannot find a good practical reason to use response types code token, code id_token token or id_token token in newly developed software, therefore, as an RP/OP implementer I don’t want to include these in future iterations of my software for the sole purpose of being able to certify for the only two response types other than code that make sense: code id_token and id_token.

This is very much related to #1362 (inclusion of PKCE as a variant) as well as (can’t find the particular issues) the possibility to now pass certification without having alg:none support or verifying ID Token signatures from the Token Endpoint.


Bitbucket status: open

Bitbucket origin: issue 2171

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.