Skip to main content

OpenID Connect

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: openid-connect
  • Manifest: docs/external-frameworks/openid-connect.json
  • Compatibility report: ./reports/openid-connect.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: openid-connect
  • Framework name: OpenID Connect
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOpenID Connect
source_referencehttps://openid.net/specs/openid-connect-core-1_0.html
source_versionOpenID Connect Core 1.0 recorded
allowed_use_boundaryidentity evidence only
claimsauthentication and interoperable identity claims
non_claimsno delegation, admissibility, or execution authority
input_artifact_typeauthentication request and tokens
output_artifact_typeidentity claims evidence
actor_or_authority_modelauthenticated identity only
evidence_modelofficial specification plus bounded crosswalk
policy_or_rule_modelprotocol validation rules
delegation_modelnot established
decision_or_result_modelauthentication evidence
execution_authority_claimfalse
receipt_or_trace_modeltoken and manifest references
reconstruction_modelclaims support actor and session reconstruction
SPE_overlapidentity evidence may inform standing review
StegVerse_ecosystem_overlapauthority and freshness boundary
fail_closed_conditionsmissing source, token context, mapping, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: openid-connect
  • Name: OpenID Connect
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/openid-connect.json
  • Source reference: https://openid.net/specs/openid-connect-core-1_0.html
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Status

Relationship type: external framework crosswalk
Evidence class: SOURCE_REVIEWED
Page completeness: COMPLETE_WITH_EXTERNAL_GATES
Runtime observation: none attached
Independent reproduction: false
Comparative testing claim allowed: false
Execution authority claim allowed: false
Maintenance owner: admissibility-wiki External Frameworks audit

Official Sources

Framework-Native Scope

OpenID Connect is an identity layer on OAuth 2.0. It enables a client to verify an end user's authentication at an OpenID Provider and obtain interoperable identity claims through ID Tokens and related endpoints.

Evidence Provenance

Evidence classCurrent evidenceStatusMissing fields
Official framework sourceCore specificationpresentpinned publication snapshot hash
Implementation sourceNo provider/client release selectedmissingproduct, version, configuration
Observed behaviorNo authentication flow capturedmissingrequest, response, token, validation output, timestamp
Reproduced behaviorNo independent rerunmissingreplay procedure, test environment, second result
StegVerse analysisBounded crosswalkpresentcommon interoperability fixture

Relationship to Admissibility

OpenID Connect asks: Did this provider authenticate the subject and issue claims acceptable to the relying party?
StegVerse Admissibility asks: Does this actor currently hold bounded authority to perform this action against this target and bind consequence?

Authentication and identity claims can contribute actor and session evidence. They do not establish current delegation, action scope, target permission, or commit-time validity.

Execution Authority Boundary

authenticated subject != authorized actor for every action
valid ID Token != current delegation
accepted issuer != consequence-binding authority
identity claim != transition admissibility

Observation Boundary

Pinned provider: none
Pinned client: none
Discovery document: none
ID Token fixture: none
Validation output: none
Timestamp and key-set snapshot: none
Independent replay: none

No interoperability or runtime result is claimed.

StegVerse Analysis

CriterionCurrent result
IdentityOIDC may establish provider-asserted subject identity within a configured trust relationship.
AuthorityAuthentication does not prove action-level authority.
PolicyIssuer, audience, nonce, signature, time, and claim-validation policy must be explicit.
DelegationDelegation requires separate scope and authority evidence.
EvidenceTokens and validation records can support reconstruction if retained securely.
ReplayabilityRequires pinned provider/client configuration, keys, claims, and validation procedure.
ReconstructabilityDepends on retained key sets, issuer metadata, token, and validation context.
Commit-time validityRequires fresh identity, delegation, policy, action, target, and validity-window checks.
Failure behaviorInvalid issuer, audience, nonce, signature, or time claims must fail closed.

Commit-Time Interoperability Contract

transition_id
issuer
subject
audience
authentication_time
id_token_digest
claim_set_digest
key_set_reference
validation_result
validation_timestamp
relying_party_id
policy_reference
delegation_reference
requested_action
target_system
validity_window

Failure Classes

Failure classAppliesNotes
Actor ambiguityyesSubject, client, operator, and executing service may differ.
Authority driftyesA valid session can outlive action authority.
Stale evidenceyesKeys, sessions, account status, and claims change.
Delegation leakageyesAuthentication may be overextended into authorization.
Replay divergenceyesProvider configuration and keys can change validation results.
Evidence-class confusionyesSource review must not be described as an observed login flow.

Machine-Readable Companions

  • Manifest: docs/external-frameworks/openid-connect.json
  • Compatibility report: docs/external-frameworks/reports/openid-connect.compatibility.json
  • Registry: docs/external-frameworks/index.json
  • Canonical inventory: static/external-frameworks/canonical-union-inventory.v1.json

Validation Completion Criteria

pin one provider and relying-party implementation
publish configuration and discovery metadata
capture a bounded token-validation flow and raw output
publish key-set snapshot, timestamp, expected result, and replay steps
complete an independent rerun
route identity evidence into a Commitment Candidate without inheriting authority

Non-Claims

OpenID Connect is not a StegVerse canonical formalism. Authenticated identity is not execution authority, current delegation, transition admissibility, certification, or general compatibility.

Challenge Path

A challenge must identify the issuer, subject or claim, validation rule, source version, supporting evidence, and requested correction. Identity assertions receive only reconstructable standing.

Next Safe Build Target

Publish one pinned provider/client token-validation fixture with raw validation output, key-set snapshot, immutable hashes, replay instructions, and an independent rerun.

This page reflects a bounded admissibility packet. Publication does not create standing.