An ID token, from OpenID Connect, carries information about who authenticated, so the application can establish a session.
Frequently asked questions
Is an ID token the same as an access token?
No, an ID token establishes who logged in; an access token grants API access. They're issued together but serve different purposes.
Who is supposed to read an ID token?
The application (relying party) that requested it, not downstream APIs, which should rely on the access token instead.
Was this definition useful?
Feedback goes to the editor who maintains this entry.
.avif)