IdentityServer3对接Salesforce Communities时User Info端点无openid scope问题
Hey there, let's dig into this frustrating issue—glad most of your authorization code flow is working, that half the battle! Here are the most common fixes to check when the User Info endpoint is complaining about missing the openid scope, even when you're sure the client is sending it:
1. Confirm openid is actually being granted by IdentityServer3
Sometimes the client sends the scope, but IdentityServer3 doesn't include it in the granted permissions.
- Fire up detailed debug logging in IdentityServer3 (set
LogLevel = LogLevel.Debugin your config) and look for the authorization response logs. Check if thescopefield in the response includesopenid. - Double-check your client configuration in IdentityServer3 to ensure
openidis in the allowed scopes list:new Client { ClientId = "your-salesforce-community-client-id", AllowedScopes = new List<string> { IdentityServerConstants.StandardScopes.OpenId, // Add other required scopes here (e.g., profile, email) }, // Rest of your client settings }
2. Verify the access token includes the openid scope
The User Info endpoint checks the access token's scope claims, not just the initial authorization request.
- Grab the access token Salesforce receives and parse it with a tool like jwt.io. Look for the
scopeclaim—ifopenidisn't listed here, that's the problem. - Make sure Salesforce is including the full scope list (including
openid) when exchanging the authorization code for an access token. Some clients accidentally omit scopes during this step.
3. Check your openid scope configuration in IdentityServer3
IdentityServer3 requires explicit setup for identity scopes like openid:
- Ensure your
Scopeconfiguration foropenidis correctly defined as an identity scope, with claims mapped properly:new Scope { Name = IdentityServerConstants.StandardScopes.OpenId, DisplayName = "OpenID Connect", Type = ScopeType.Identity, IncludeAllClaimsForUser = true, // Or specify individual claims if needed }
4. Validate Salesforce Connected App settings
Salesforce might be dropping the openid scope on its end:
- In your Salesforce Connected App, go to API (Enable OAuth Settings) → Selected OAuth Scopes and confirm "OpenID" is checked. It's easy to overlook this checkbox when setting up the app.
- Verify that Salesforce is sending the same scope list (including
openid) in both the initial authorization request and the token exchange request.
5. Debug the User Info request flow
If all else fails, trace the full request path:
- Use the IdentityServer3 logs to see exactly what scope the User Info endpoint is checking. Look for lines like "Checking scope requirements for user info request"—this will show which scopes the endpoint expects vs. what's present in the token.
- Confirm the access token being sent to the User Info endpoint is the same one issued by IdentityServer3 (no tampering or scope filtering happening on Salesforce's side).
Start with checking the access token's scope claims and IdentityServer3 debug logs—those usually point straight to the root cause. Don't sleep on Salesforce's Connected App settings either; small oversights there can cause big headaches!
内容的提问来源于stack exchange,提问作者Andrew Greenman

