why id_token is passed via url with fragment identifier instead query string?

Viewed 1699

After the openid authentication, id_token (jwt) is passed to the client is through URI fragment instead of query string which makes impossible to read by the server. Whats the real motto behind this. Whats the benefits out of this

2 Answers

The fragment is supposed to be stripped by the user agent (e.g. browser) before loading the URL so the fragment doesn't end up in server side logs.

One should be aware that recent changes in browser implementations make the assumption above questionable and it may be safer to rely on an Authorization Code flow.

Was just going through the same curiosity and found the answer:

As per the specs.

Returning the id_token in a fragment reduces the likelihood that the id_token leaks during transport and mitigates the associated risks to the privacy of the user (Resource Owner).

You can get query string by adding response_mode=query but that is not recommended. As that is for Authorization Code flow.

Related