OAuth2 and OIDCmedium3-5 years

A front-end team signs users in with OpenID Connect and sends the **ID token** to your Spring Boot API as the bearer token, because "it has the user's email and it's a signed JWT". Your API accepts it. What is wrong with the arrangement, which party is your API in OAuth terms, and what should the API check instead?

In OAuth terms the API is the resource server: it receives and validates access tokens; it does not issue them, and it is not the client. The client is the front end the user is using. OIDC issues three tokens with three audiences: the access token is for the resource server, the ID token is for the client (it tells the client who signed in), and the refresh token is for the authorization server. The ID token's aud is the client's id, so a correctly configured resource server rejects it; the API accepting it means its audience check is missing, and it is accepting a token that was never issued to authorize calls to it. The front end should send the access token, and the API should validate issuer, audience and expiry on it.

The lesson behind it →
More on OAuth2 and OIDC