You sir are a talented speaker. I'm finally getting this!! Thank you for making things easy to understand!
@Oggie2010 Жыл бұрын
Claims are metadata about the End user. Scope are authorization limitations for the Client. Both have a purpose and should not be confused (which is easy to do if you only focus on End User Identification extension on top of OAuth2 (OIDC) and not so much on the core OAuth2 purpose of Client Authorization). I prefer to see Scopes as subset Authorzation given to the Client by the End User. I.e allowing a specific client to read your order history but not place new orders on your behalf. Claims are Metadata about the End user.