Skip to content

OpenID Connect Implicit Client Profile

This section provides information about the expected requests and the relevant responses that the MWARE IAM would generate for the OpenID Connect Implicit Client flow.

Register a service provider

To register your application as a service provider in the MWARE IAM:

  1. Log in to the MWARE IAM Management Console using administrator credentials.

  2. Go to Main > Identity > Service Providers > Add.

  3. Enter a Service Provider Name. Optionally, enter a Description.

  4. Click Register.

Configure the service provider

Make the following changes to the created service provider.

  1. Expand Inbound Authentication Configuration > OAuth/OpenID Connect Configuration and click Configure.

  2. Enter the Callback Url.


    The Callback Url is the exact location in the service provider's application to which an access token will be sent. This URL should be the URL of the page that the user is redirected to after successful authentication.

  3. Click Add. Note the OAuth Client Key and OAuth Client Secret that appear.


To configure more advanced configurations, see OAuth/OpenID Connect Configurations.

Try out the flows

Let's try out the different OIDC hybrid flows by specifyin the following response types in the authorization request.

Get id token

  1. Send the following request using a browser-based application.

    Request Format


    Sample Request



    The nonce value is a mandatory to receive an Id Token.

  2. You will receive the following response upon successful authorization.

    Resonse Format


    Sample Response


    Given below is the Base64 decoded value of the Id Token:

      "isk": "d835ba8f2167f4bb4858d32ef6cfc7fbfb1a2711c04a09ffc197248ec2689fca",
      "aud": "CVyQeM5P33gfN80vur3NcxzPgHwa",
      "sub": "admin",
      "azp": "CVyQeM5P33gfN80vur3NcxzPgHwa",
      "amr": [
      "iss": "https://localhost:9443/oauth2/token",
      "exp": 1615875984,
      "iat": 1615872384,
      "nonce": "abc"


    The Id Token does not contain the at_hash value because no access token is generated. An access token is required to calculate the at_hash value.

Get access token and id token

  1. Send the following request using a browser-based application.

    Request Format

    https://<host>:<port>/oauth2/authorize?response_type=id_token token&client_id=<oauth_client_key>&redirect_uri=<callback_url>&nonce=<nonce_value>&scope=openid

    Sample Request

    https://localhost:9443/oauth2/authorize?response_type=id_token token&client_id=NgTICXFPYnt7ETUm6Fc8NMU8K38a&redirect_uri=http://wso2is.local:8080/playground2/oauth2client&nonce=abc&scope=openid


    The nonce value is a mandatory to receive an Id Token.

  2. You will receive the following sample response upon successful authorization. Note that both the access token and the ID Token are returned to the client.

    Response Format


    Sample Response

