Skip to main content

Claims reviews

Not served by the id service: sent by it, to a service that owns a scope, at <URL>/api/v1alpha1/claimsreviews or FG_ID_SERVICE_<NAME>_CLAIMS_ENDPOINT.

The OpenAPI document describes it under webhooks.

POST /api/v1alpha1/claimsreviews
Authorization: Bearer <JWT, typ fg-claims-review+jwt>
Content-Type: application/json
request
uidecho it in the response
purposePreview while the person decides, Release when the claims go out
subjectthe person, as sub
clientthe service the claims are for, { id, name }
scopes, claimswhat is asked for
response
uidthe request's
claimsthe claims; anything the scopes do not carry is dropped
reasonsoptional: what was withheld and why, shown to the person

Answer within three seconds, or the claims are left out.