You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer3对接Salesforce Communities时User Info端点无openid scope问题

Troubleshooting "User Info endpoint not finding openid scope" with IdentityServer3 + Salesforce Communities

Hey there, let's dig into this frustrating issue—glad most of your authorization code flow is working, that half the battle! Here are the most common fixes to check when the User Info endpoint is complaining about missing the openid scope, even when you're sure the client is sending it:

1. Confirm openid is actually being granted by IdentityServer3

Sometimes the client sends the scope, but IdentityServer3 doesn't include it in the granted permissions.

  • Fire up detailed debug logging in IdentityServer3 (set LogLevel = LogLevel.Debug in your config) and look for the authorization response logs. Check if the scope field in the response includes openid.
  • Double-check your client configuration in IdentityServer3 to ensure openid is in the allowed scopes list:
    new Client
    {
        ClientId = "your-salesforce-community-client-id",
        AllowedScopes = new List<string>
        {
            IdentityServerConstants.StandardScopes.OpenId,
            // Add other required scopes here (e.g., profile, email)
        },
        // Rest of your client settings
    }
    

2. Verify the access token includes the openid scope

The User Info endpoint checks the access token's scope claims, not just the initial authorization request.

  • Grab the access token Salesforce receives and parse it with a tool like jwt.io. Look for the scope claim—if openid isn't listed here, that's the problem.
  • Make sure Salesforce is including the full scope list (including openid) when exchanging the authorization code for an access token. Some clients accidentally omit scopes during this step.

3. Check your openid scope configuration in IdentityServer3

IdentityServer3 requires explicit setup for identity scopes like openid:

  • Ensure your Scope configuration for openid is correctly defined as an identity scope, with claims mapped properly:
    new Scope
    {
        Name = IdentityServerConstants.StandardScopes.OpenId,
        DisplayName = "OpenID Connect",
        Type = ScopeType.Identity,
        IncludeAllClaimsForUser = true, // Or specify individual claims if needed
    }
    

4. Validate Salesforce Connected App settings

Salesforce might be dropping the openid scope on its end:

  • In your Salesforce Connected App, go to API (Enable OAuth Settings) → Selected OAuth Scopes and confirm "OpenID" is checked. It's easy to overlook this checkbox when setting up the app.
  • Verify that Salesforce is sending the same scope list (including openid) in both the initial authorization request and the token exchange request.

5. Debug the User Info request flow

If all else fails, trace the full request path:

  • Use the IdentityServer3 logs to see exactly what scope the User Info endpoint is checking. Look for lines like "Checking scope requirements for user info request"—this will show which scopes the endpoint expects vs. what's present in the token.
  • Confirm the access token being sent to the User Info endpoint is the same one issued by IdentityServer3 (no tampering or scope filtering happening on Salesforce's side).

Start with checking the access token's scope claims and IdentityServer3 debug logs—those usually point straight to the root cause. Don't sleep on Salesforce's Connected App settings either; small oversights there can cause big headaches!

内容的提问来源于stack exchange,提问作者Andrew Greenman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:00:06