Is it a security risk to include sensitive PII such as date of birth, email address, and phone number directly in an OpenID Connect ID token (id_token)? My development team insists this aligns with industry standards and is mitigated by controls like ensuring the token never leaves the user’s device and implementing TLS for all communications— but I’m concerned about PII etc, is it acceptable approach.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| tokenInfo api is not working | 4 | 4480 | July 26, 2019 | |
| After google signUp how will we get details of the user signed up | 2 | 3855 | March 2, 2018 | |
| Missing birth date in profile claims | 3 | 8421 | August 2, 2019 | |
| Generate id_token | 2 | 3984 | March 2, 2018 | |
| Retrieve user info post social connection signup | 2 | 3950 | December 14, 2018 |