FHIR IG analytics| Package | hl7.fhir.us.identity-matching |
| Resource Type | StructureDefinition |
| Id | StructureDefinition-oidc-token.json |
| FHIR Version | R4 |
| Source | https://build.fhir.org/ig/HL7/fhir-identity-matching-ig/StructureDefinition-oidc-token.html |
| URL | http://hl7.org/fhir/us/identity-matching/StructureDefinition/oidc-token |
| Version | 3.0.0-current |
| Status | active |
| Date | 2026-10-01T12:59:11+00:00 |
| Name | OIDCToken |
| Title | OpenID Connect ID Token |
| Realm | us |
| Authority | hl7 |
| Description | A logical representation of common JWT registered claims, OpenID Connect ID Token claims, and the OIDC for Identity Assurance `verified_claims` object. It is not a JWT wire-format or signature model. See [RFC 7519](https://www.rfc-editor.org/rfc/rfc7519), [OpenID Connect Core](https://openid.net/specs/openid-connect-core-1_0.html), and [OpenID Connect for Identity Assurance](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html). |
| Type | http://hl7.org/fhir/us/identity-matching/StructureDefinition/oidc-token |
| Kind | logical |
No resources found
No resources found
Note: links and images are rebased to the (stated) source
Generated Narrative: StructureDefinition oidc-token
| Name | Flags | Card. | Type | Description & Constraints |
|---|---|---|---|---|
![]() | 0..* | Base | OpenID Connect ID Token | |
![]() ![]() | 1..1 | uri | Issuer | |
![]() ![]() | 1..1 | string | Subject identifier | |
![]() ![]() | 1..* | string | Audience identifiers | |
![]() ![]() | 1..1 | decimal | Expiration time as a JWT NumericDate | |
![]() ![]() | 1..1 | decimal | Issued-at time as a JWT NumericDate | |
![]() ![]() | 0..1 | decimal | Not-before time as a JWT NumericDate | |
![]() ![]() | 0..1 | string | JWT identifier | |
![]() ![]() | 0..1 | decimal | Time of end-user authentication as a JWT NumericDate | |
![]() ![]() | 0..1 | string | Nonce supplied by the relying party | |
![]() ![]() | 0..1 | string | Authentication context class reference | |
![]() ![]() | 0..* | string | Authentication methods used | |
![]() ![]() | 0..1 | string | Authorized party | |
![]() ![]() | 0..1 | string | Access token hash | |
![]() ![]() | 0..1 | string | Authorization code hash | |
![]() ![]() | 0..1 | string | Full name | |
![]() ![]() | 0..1 | string | Given name | |
![]() ![]() | 0..1 | string | Middle name(s) | |
![]() ![]() | 0..1 | string | Family name | |
![]() ![]() | 0..1 | string | Casual name | |
![]() ![]() | 0..1 | string | Preferred username | |
![]() ![]() | 0..1 | uri | Profile page URL | |
![]() ![]() | 0..1 | uri | Profile picture URL | |
![]() ![]() | 0..1 | uri | Web page URL | |
![]() ![]() | 0..1 | string | Email address | |
![]() ![]() | 0..1 | boolean | Whether the email address was verified | |
![]() ![]() | 0..1 | string | Gender | |
![]() ![]() | 0..1 | date | Birth date | |
![]() ![]() | 0..1 | string | Time zone | |
![]() ![]() | 0..1 | string | Locale | |
![]() ![]() | 0..1 | string | Phone number | |
![]() ![]() | 0..1 | boolean | Whether the phone number was verified | |
![]() ![]() | 0..1 | BackboneElement | Postal address | |
![]() ![]() ![]() | 0..1 | string | Full formatted address | |
![]() ![]() ![]() | 0..1 | string | Street address | |
![]() ![]() ![]() | 0..1 | string | City or locality | |
![]() ![]() ![]() | 0..1 | string | State, province, or region | |
![]() ![]() ![]() | 0..1 | string | Postal code | |
![]() ![]() ![]() | 0..1 | string | Country | |
![]() ![]() | 0..1 | decimal | Time the end-user information was last updated as a JWT NumericDate | |
![]() ![]() | 0..* | BackboneElement | Verified claims with their verification context | |
![]() ![]() ![]() | 0..1 | BackboneElement | Verification context | |
![]() ![]() ![]() ![]() | 0..1 | string | Trust framework | |
![]() ![]() ![]() ![]() | 0..1 | dateTime | Time of verification | |
![]() ![]() ![]() ![]() | 0..1 | string | Assurance level | |
![]() ![]() ![]() | 0..1 | BackboneElement | Identity claims covered by the verification | |
![]() ![]() ![]() ![]() | 0..1 | string | Verified given name | |
![]() ![]() ![]() ![]() | 0..1 | string | Verified middle name(s) | |
![]() ![]() ![]() ![]() | 0..1 | string | Verified family name | |
![]() ![]() ![]() ![]() | 0..1 | date | Verified birth date | |
![]() ![]() ![]() ![]() | 0..1 | string | Verified email address | |
![]() ![]() ![]() ![]() | 0..1 | string | Verified phone number | |
![]() ![]() ![]() ![]() | 0..1 | string | Proposal-specific claim for the last four SSN digits | |
{
"resourceType": "StructureDefinition",
"id": "oidc-token",
"text": {
"status": "extensions",
"div": "<!-- snip (see above) -->"
},
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
"valueCode": "pa"
},
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm",
"valueInteger": 2,
"_valueInteger": {
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
"valueCanonical": "http://hl7.org/fhir/us/identity-matching/ImplementationGuide/hl7.fhir.us.identity-matching"
}
]
}
},
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status",
"valueCode": "trial-use",
"_valueCode": {
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
"valueCanonical": "http://hl7.org/fhir/us/identity-matching/ImplementationGuide/hl7.fhir.us.identity-matching"
}
]
}
}
],
"url": "http://hl7.org/fhir/us/identity-matching/StructureDefinition/oidc-token",
"identifier": [
{
"system": "urn:ietf:rfc:3986",
"value": "urn:oid:2.16.840.1.113883.4.642.40.81.42.20"
}
],
"version": "3.0.0-current",
"name": "OIDCToken",
"title": "OpenID Connect ID Token",
"status": "active",
"date": "2026-10-01T12:59:11+00:00",
"publisher": "HL7 International / Patient Administration",
"contact": [
{
"name": "HL7 International / Patient Administration",
"telecom": [
{
"system": "url",
"value": "http://www.hl7.org/Special/committees/pafm"
}
]
}
],
"description": "A logical representation of common JWT registered claims, OpenID Connect ID Token claims, and the OIDC for Identity Assurance `verified_claims` object. It is not a JWT wire-format or signature model. See [RFC 7519](https://www.rfc-editor.org/rfc/rfc7519), [OpenID Connect Core](https://openid.net/specs/openid-connect-core-1_0.html), and [OpenID Connect for Identity Assurance](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html).",
"jurisdiction": [
{
"coding": [
{
"system": "urn:iso:std:iso:3166",
"code": "US"
}
]
}
],
"fhirVersion": "4.0.1",
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"uri": "http://hl7.org/fhir/us/identity-matching/StructureDefinition/identity-assertion",
"name": "OpenID Connect ID Token to Identity Assertion",
"comment": "Informative reverse mapping from the local OIDCToken logical model to IdentityAssertion. OIDC claims are often singular while IdentityAssertion permits repetitions, and the verified_claims values should be preferred over corresponding unverified top-level claims when present. JWT issuance metadata and claims without an IdentityAssertion equivalent are not mapped."
}
],
"kind": "logical",
"abstract": false,
"type": "http://hl7.org/fhir/us/identity-matching/StructureDefinition/oidc-token",
"baseDefinition": "http://hl7.org/fhir/StructureDefinition/Base",
"derivation": "specialization",
"snapshot": {
"extension": [
{
"url": "http://hl7.org/fhir/tools/StructureDefinition/snapshot-base-version",
"valueString": "4.0.1"
}
],
"element": [
{
"id": "oidc-token",
"path": "oidc-token",
"short": "OpenID Connect ID Token",
"definition": "A logical representation of common JWT registered claims, OpenID Connect ID Token claims, and the OIDC for Identity Assurance `verified_claims` object. It is not a JWT wire-format or signature model. See [RFC 7519](https://www.rfc-editor.org/rfc/rfc7519), [OpenID Connect Core](https://openid.net/specs/openid-connect-core-1_0.html), and [OpenID Connect for Identity Assurance](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html).",
"min": 0,
"max": "*",
"base": {
"path": "Base",
"min": 0,
"max": "*"
},
"isModifier": false,
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion"
}
]
},
{
"id": "oidc-token.iss",
"path": "oidc-token.iss",
"short": "Issuer",
"definition": "Issuer",
"min": 1,
"max": "1",
"base": {
"path": "oidc-token.iss",
"min": 1,
"max": "1"
},
"type": [
{
"code": "uri"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.masterIdentifier.system",
"comment": "Use as the identifier system only when this is the namespace for sub."
}
]
},
{
"id": "oidc-token.sub",
"path": "oidc-token.sub",
"short": "Subject identifier",
"definition": "Subject identifier",
"min": 1,
"max": "1",
"base": {
"path": "oidc-token.sub",
"min": 1,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.masterIdentifier.value"
}
]
},
{
"id": "oidc-token.aud",
"path": "oidc-token.aud",
"short": "Audience identifiers",
"definition": "Audience identifiers",
"min": 1,
"max": "*",
"base": {
"path": "oidc-token.aud",
"min": 1,
"max": "*"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.exp",
"path": "oidc-token.exp",
"short": "Expiration time as a JWT NumericDate",
"definition": "Expiration time as a JWT NumericDate",
"min": 1,
"max": "1",
"base": {
"path": "oidc-token.exp",
"min": 1,
"max": "1"
},
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.iat",
"path": "oidc-token.iat",
"short": "Issued-at time as a JWT NumericDate",
"definition": "Issued-at time as a JWT NumericDate",
"min": 1,
"max": "1",
"base": {
"path": "oidc-token.iat",
"min": 1,
"max": "1"
},
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.nbf",
"path": "oidc-token.nbf",
"short": "Not-before time as a JWT NumericDate",
"definition": "Not-before time as a JWT NumericDate",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.nbf",
"min": 0,
"max": "1"
},
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.jti",
"path": "oidc-token.jti",
"short": "JWT identifier",
"definition": "JWT identifier",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.jti",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.auth-time",
"path": "oidc-token.auth_time",
"short": "Time of end-user authentication as a JWT NumericDate",
"definition": "Time of end-user authentication as a JWT NumericDate",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.auth_time",
"min": 0,
"max": "1"
},
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.nonce",
"path": "oidc-token.nonce",
"short": "Nonce supplied by the relying party",
"definition": "Nonce supplied by the relying party",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.nonce",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.acr",
"path": "oidc-token.acr",
"short": "Authentication context class reference",
"definition": "Authentication context class reference",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.acr",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.amr",
"path": "oidc-token.amr",
"short": "Authentication methods used",
"definition": "Authentication methods used",
"min": 0,
"max": "*",
"base": {
"path": "oidc-token.amr",
"min": 0,
"max": "*"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.azp",
"path": "oidc-token.azp",
"short": "Authorized party",
"definition": "Authorized party",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.azp",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.at-hash",
"path": "oidc-token.at_hash",
"short": "Access token hash",
"definition": "Access token hash",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.at_hash",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.c-hash",
"path": "oidc-token.c_hash",
"short": "Authorization code hash",
"definition": "Authorization code hash",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.c_hash",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.name",
"path": "oidc-token.name",
"short": "Full name",
"definition": "Full name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.given-name",
"path": "oidc-token.given_name",
"short": "Given name",
"definition": "Given name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.given_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.first"
}
]
},
{
"id": "oidc-token.middle-name",
"path": "oidc-token.middle_name",
"short": "Middle name(s)",
"definition": "Middle name(s)",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.middle_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.middle"
}
]
},
{
"id": "oidc-token.family-name",
"path": "oidc-token.family_name",
"short": "Family name",
"definition": "Family name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.family_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.last"
}
]
},
{
"id": "oidc-token.nickname",
"path": "oidc-token.nickname",
"short": "Casual name",
"definition": "Casual name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.nickname",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.preferred-username",
"path": "oidc-token.preferred_username",
"short": "Preferred username",
"definition": "Preferred username",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.preferred_username",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.profile",
"path": "oidc-token.profile",
"short": "Profile page URL",
"definition": "Profile page URL",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.profile",
"min": 0,
"max": "1"
},
"type": [
{
"code": "uri"
}
]
},
{
"id": "oidc-token.picture",
"path": "oidc-token.picture",
"short": "Profile picture URL",
"definition": "Profile picture URL",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.picture",
"min": 0,
"max": "1"
},
"type": [
{
"code": "uri"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.photo.url",
"comment": "Convert the URI to an Attachment URL."
}
]
},
{
"id": "oidc-token.website",
"path": "oidc-token.website",
"short": "Web page URL",
"definition": "Web page URL",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.website",
"min": 0,
"max": "1"
},
"type": [
{
"code": "uri"
}
]
},
{
"id": "oidc-token.email",
"path": "oidc-token.email",
"short": "Email address",
"definition": "Email address",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.email",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.emails.address"
}
]
},
{
"id": "oidc-token.email-verified",
"path": "oidc-token.email_verified",
"short": "Whether the email address was verified",
"definition": "Whether the email address was verified",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.email_verified",
"min": 0,
"max": "1"
},
"type": [
{
"code": "boolean"
}
]
},
{
"id": "oidc-token.gender",
"path": "oidc-token.gender",
"short": "Gender",
"definition": "Gender",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.gender",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.gender"
}
]
},
{
"id": "oidc-token.birthdate",
"path": "oidc-token.birthdate",
"short": "Birth date",
"definition": "Birth date",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.birthdate",
"min": 0,
"max": "1"
},
"type": [
{
"code": "date"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.birthDate"
}
]
},
{
"id": "oidc-token.zoneinfo",
"path": "oidc-token.zoneinfo",
"short": "Time zone",
"definition": "Time zone",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.zoneinfo",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.locale",
"path": "oidc-token.locale",
"short": "Locale",
"definition": "Locale",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.locale",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.phone-number",
"path": "oidc-token.phone_number",
"short": "Phone number",
"definition": "Phone number",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.phone_number",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.phoneNumbers.number"
}
]
},
{
"id": "oidc-token.phone-number-verified",
"path": "oidc-token.phone_number_verified",
"short": "Whether the phone number was verified",
"definition": "Whether the phone number was verified",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.phone_number_verified",
"min": 0,
"max": "1"
},
"type": [
{
"code": "boolean"
}
]
},
{
"id": "oidc-token.address",
"path": "oidc-token.address",
"short": "Postal address",
"definition": "Postal address",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address",
"min": 0,
"max": "1"
},
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses",
"comment": "OIDC carries one address object; IdentityAssertion permits multiple addresses."
}
]
},
{
"id": "oidc-token.address.id",
"path": "oidc-token.address.id",
"representation": [
"xmlAttr"
],
"short": "Unique id for inter-element referencing",
"definition": "Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.",
"min": 0,
"max": "1",
"base": {
"path": "Element.id",
"min": 0,
"max": "1"
},
"type": [
{
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
"valueUrl": "string"
}
],
"code": "http://hl7.org/fhirpath/System.String"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.address.extension",
"path": "oidc-token.address.extension",
"slicing": {
"discriminator": [
{
"type": "value",
"path": "url"
}
],
"description": "Extensions are always sliced by (at least) url",
"rules": "open"
},
"short": "Additional content defined by implementations",
"definition": "May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"alias": [
"extensions",
"user content"
],
"min": 0,
"max": "*",
"base": {
"path": "Element.extension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.address.modifierExtension",
"path": "oidc-token.address.modifierExtension",
"short": "Extensions that cannot be ignored even if unrecognized",
"definition": "May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.\n\nModifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"requirements": "Modifier extensions allow for extensions that *cannot* be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the [definition of modifier extensions](http://hl7.org/fhir/R4/extensibility.html#modifierExtension).",
"alias": [
"extensions",
"user content",
"modifiers"
],
"min": 0,
"max": "*",
"base": {
"path": "BackboneElement.modifierExtension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": true,
"isModifierReason": "Modifier extensions are expected to modify the meaning or interpretation of the element that contains them",
"isSummary": true,
"mapping": [
{
"identity": "rim",
"map": "N/A"
}
]
},
{
"id": "oidc-token.address.formatted",
"path": "oidc-token.address.formatted",
"short": "Full formatted address",
"definition": "Full formatted address",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.formatted",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.address.street-address",
"path": "oidc-token.address.street_address",
"short": "Street address",
"definition": "Street address",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.street_address",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.line",
"comment": "Split into lines when needed."
}
]
},
{
"id": "oidc-token.address.locality",
"path": "oidc-token.address.locality",
"short": "City or locality",
"definition": "City or locality",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.locality",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.city"
}
]
},
{
"id": "oidc-token.address.region",
"path": "oidc-token.address.region",
"short": "State, province, or region",
"definition": "State, province, or region",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.region",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.state"
}
]
},
{
"id": "oidc-token.address.postal-code",
"path": "oidc-token.address.postal_code",
"short": "Postal code",
"definition": "Postal code",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.postal_code",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.postalCode"
}
]
},
{
"id": "oidc-token.address.country",
"path": "oidc-token.address.country",
"short": "Country",
"definition": "Country",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.address.country",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.country"
}
]
},
{
"id": "oidc-token.updated-at",
"path": "oidc-token.updated_at",
"short": "Time the end-user information was last updated as a JWT NumericDate",
"definition": "Time the end-user information was last updated as a JWT NumericDate",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.updated_at",
"min": 0,
"max": "1"
},
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.verified-claims",
"path": "oidc-token.verified_claims",
"short": "Verified claims with their verification context",
"definition": "Verified claims with their verification context",
"min": 0,
"max": "*",
"base": {
"path": "oidc-token.verified_claims",
"min": 0,
"max": "*"
},
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
}
]
},
{
"id": "oidc-token.verified-claims.id",
"path": "oidc-token.verified_claims.id",
"representation": [
"xmlAttr"
],
"short": "Unique id for inter-element referencing",
"definition": "Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.",
"min": 0,
"max": "1",
"base": {
"path": "Element.id",
"min": 0,
"max": "1"
},
"type": [
{
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
"valueUrl": "string"
}
],
"code": "http://hl7.org/fhirpath/System.String"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.extension",
"path": "oidc-token.verified_claims.extension",
"slicing": {
"discriminator": [
{
"type": "value",
"path": "url"
}
],
"description": "Extensions are always sliced by (at least) url",
"rules": "open"
},
"short": "Additional content defined by implementations",
"definition": "May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"alias": [
"extensions",
"user content"
],
"min": 0,
"max": "*",
"base": {
"path": "Element.extension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.modifierExtension",
"path": "oidc-token.verified_claims.modifierExtension",
"short": "Extensions that cannot be ignored even if unrecognized",
"definition": "May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.\n\nModifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"requirements": "Modifier extensions allow for extensions that *cannot* be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the [definition of modifier extensions](http://hl7.org/fhir/R4/extensibility.html#modifierExtension).",
"alias": [
"extensions",
"user content",
"modifiers"
],
"min": 0,
"max": "*",
"base": {
"path": "BackboneElement.modifierExtension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": true,
"isModifierReason": "Modifier extensions are expected to modify the meaning or interpretation of the element that contains them",
"isSummary": true,
"mapping": [
{
"identity": "rim",
"map": "N/A"
}
]
},
{
"id": "oidc-token.verified-claims.verification",
"path": "oidc-token.verified_claims.verification",
"short": "Verification context",
"definition": "Verification context",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.verification",
"min": 0,
"max": "1"
},
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
}
]
},
{
"id": "oidc-token.verified-claims.verification.id",
"path": "oidc-token.verified_claims.verification.id",
"representation": [
"xmlAttr"
],
"short": "Unique id for inter-element referencing",
"definition": "Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.",
"min": 0,
"max": "1",
"base": {
"path": "Element.id",
"min": 0,
"max": "1"
},
"type": [
{
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
"valueUrl": "string"
}
],
"code": "http://hl7.org/fhirpath/System.String"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.verification.extension",
"path": "oidc-token.verified_claims.verification.extension",
"slicing": {
"discriminator": [
{
"type": "value",
"path": "url"
}
],
"description": "Extensions are always sliced by (at least) url",
"rules": "open"
},
"short": "Additional content defined by implementations",
"definition": "May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"alias": [
"extensions",
"user content"
],
"min": 0,
"max": "*",
"base": {
"path": "Element.extension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.verification.modifierExtension",
"path": "oidc-token.verified_claims.verification.modifierExtension",
"short": "Extensions that cannot be ignored even if unrecognized",
"definition": "May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.\n\nModifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"requirements": "Modifier extensions allow for extensions that *cannot* be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the [definition of modifier extensions](http://hl7.org/fhir/R4/extensibility.html#modifierExtension).",
"alias": [
"extensions",
"user content",
"modifiers"
],
"min": 0,
"max": "*",
"base": {
"path": "BackboneElement.modifierExtension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": true,
"isModifierReason": "Modifier extensions are expected to modify the meaning or interpretation of the element that contains them",
"isSummary": true,
"mapping": [
{
"identity": "rim",
"map": "N/A"
}
]
},
{
"id": "oidc-token.verified-claims.verification.trust-framework",
"path": "oidc-token.verified_claims.verification.trust_framework",
"short": "Trust framework",
"definition": "Trust framework",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.verification.trust_framework",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.verified-claims.verification.time",
"path": "oidc-token.verified_claims.verification.time",
"short": "Time of verification",
"definition": "Time of verification",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.verification.time",
"min": 0,
"max": "1"
},
"type": [
{
"code": "dateTime"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.assuranceDate"
}
]
},
{
"id": "oidc-token.verified-claims.verification.assurance-level",
"path": "oidc-token.verified_claims.verification.assurance_level",
"short": "Assurance level",
"definition": "Assurance level",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.verification.assurance_level",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.assuranceLevel"
}
]
},
{
"id": "oidc-token.verified-claims.claims",
"path": "oidc-token.verified_claims.claims",
"short": "Identity claims covered by the verification",
"definition": "Identity claims covered by the verification",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims",
"min": 0,
"max": "1"
},
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
}
]
},
{
"id": "oidc-token.verified-claims.claims.id",
"path": "oidc-token.verified_claims.claims.id",
"representation": [
"xmlAttr"
],
"short": "Unique id for inter-element referencing",
"definition": "Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.",
"min": 0,
"max": "1",
"base": {
"path": "Element.id",
"min": 0,
"max": "1"
},
"type": [
{
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
"valueUrl": "string"
}
],
"code": "http://hl7.org/fhirpath/System.String"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.claims.extension",
"path": "oidc-token.verified_claims.claims.extension",
"slicing": {
"discriminator": [
{
"type": "value",
"path": "url"
}
],
"description": "Extensions are always sliced by (at least) url",
"rules": "open"
},
"short": "Additional content defined by implementations",
"definition": "May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"alias": [
"extensions",
"user content"
],
"min": 0,
"max": "*",
"base": {
"path": "Element.extension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "oidc-token.verified-claims.claims.modifierExtension",
"path": "oidc-token.verified_claims.claims.modifierExtension",
"short": "Extensions that cannot be ignored even if unrecognized",
"definition": "May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.\n\nModifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"requirements": "Modifier extensions allow for extensions that *cannot* be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the [definition of modifier extensions](http://hl7.org/fhir/R4/extensibility.html#modifierExtension).",
"alias": [
"extensions",
"user content",
"modifiers"
],
"min": 0,
"max": "*",
"base": {
"path": "BackboneElement.modifierExtension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": true,
"isModifierReason": "Modifier extensions are expected to modify the meaning or interpretation of the element that contains them",
"isSummary": true,
"mapping": [
{
"identity": "rim",
"map": "N/A"
}
]
},
{
"id": "oidc-token.verified-claims.claims.given-name",
"path": "oidc-token.verified_claims.claims.given_name",
"short": "Verified given name",
"definition": "Verified given name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.given_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.first",
"comment": "Prefer this verified value over given_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.middle-name",
"path": "oidc-token.verified_claims.claims.middle_name",
"short": "Verified middle name(s)",
"definition": "Verified middle name(s)",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.middle_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.middle",
"comment": "Prefer this verified value over middle_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.family-name",
"path": "oidc-token.verified_claims.claims.family_name",
"short": "Verified family name",
"definition": "Verified family name",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.family_name",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.last",
"comment": "Prefer this verified value over family_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.birthdate",
"path": "oidc-token.verified_claims.claims.birthdate",
"short": "Verified birth date",
"definition": "Verified birth date",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.birthdate",
"min": 0,
"max": "1"
},
"type": [
{
"code": "date"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.birthDate",
"comment": "Prefer this verified value over birthdate when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.email",
"path": "oidc-token.verified_claims.claims.email",
"short": "Verified email address",
"definition": "Verified email address",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.email",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.emails.address",
"comment": "Prefer this verified value over email when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.phone-number",
"path": "oidc-token.verified_claims.claims.phone_number",
"short": "Verified phone number",
"definition": "Verified phone number",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.phone_number",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.phoneNumbers.number",
"comment": "Prefer this verified value over phone_number when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.ssn-last4",
"path": "oidc-token.verified_claims.claims.ssn_last4",
"short": "Proposal-specific claim for the last four SSN digits",
"definition": "Proposal-specific claim for the last four SSN digits",
"min": 0,
"max": "1",
"base": {
"path": "oidc-token.verified_claims.claims.ssn_last4",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
}
]
},
"differential": {
"element": [
{
"id": "oidc-token",
"path": "oidc-token",
"short": "OpenID Connect ID Token",
"definition": "A logical representation of common JWT registered claims, OpenID Connect ID Token claims, and the OIDC for Identity Assurance `verified_claims` object. It is not a JWT wire-format or signature model. See [RFC 7519](https://www.rfc-editor.org/rfc/rfc7519), [OpenID Connect Core](https://openid.net/specs/openid-connect-core-1_0.html), and [OpenID Connect for Identity Assurance](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html).",
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion"
}
]
},
{
"id": "oidc-token.iss",
"path": "oidc-token.iss",
"short": "Issuer",
"definition": "Issuer",
"min": 1,
"max": "1",
"type": [
{
"code": "uri"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.masterIdentifier.system",
"comment": "Use as the identifier system only when this is the namespace for sub."
}
]
},
{
"id": "oidc-token.sub",
"path": "oidc-token.sub",
"short": "Subject identifier",
"definition": "Subject identifier",
"min": 1,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.masterIdentifier.value"
}
]
},
{
"id": "oidc-token.aud",
"path": "oidc-token.aud",
"short": "Audience identifiers",
"definition": "Audience identifiers",
"min": 1,
"max": "*",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.exp",
"path": "oidc-token.exp",
"short": "Expiration time as a JWT NumericDate",
"definition": "Expiration time as a JWT NumericDate",
"min": 1,
"max": "1",
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.iat",
"path": "oidc-token.iat",
"short": "Issued-at time as a JWT NumericDate",
"definition": "Issued-at time as a JWT NumericDate",
"min": 1,
"max": "1",
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.nbf",
"path": "oidc-token.nbf",
"short": "Not-before time as a JWT NumericDate",
"definition": "Not-before time as a JWT NumericDate",
"min": 0,
"max": "1",
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.jti",
"path": "oidc-token.jti",
"short": "JWT identifier",
"definition": "JWT identifier",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.auth-time",
"path": "oidc-token.auth_time",
"short": "Time of end-user authentication as a JWT NumericDate",
"definition": "Time of end-user authentication as a JWT NumericDate",
"min": 0,
"max": "1",
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.nonce",
"path": "oidc-token.nonce",
"short": "Nonce supplied by the relying party",
"definition": "Nonce supplied by the relying party",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.acr",
"path": "oidc-token.acr",
"short": "Authentication context class reference",
"definition": "Authentication context class reference",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.amr",
"path": "oidc-token.amr",
"short": "Authentication methods used",
"definition": "Authentication methods used",
"min": 0,
"max": "*",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.azp",
"path": "oidc-token.azp",
"short": "Authorized party",
"definition": "Authorized party",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.at-hash",
"path": "oidc-token.at_hash",
"short": "Access token hash",
"definition": "Access token hash",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.c-hash",
"path": "oidc-token.c_hash",
"short": "Authorization code hash",
"definition": "Authorization code hash",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.name",
"path": "oidc-token.name",
"short": "Full name",
"definition": "Full name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.given-name",
"path": "oidc-token.given_name",
"short": "Given name",
"definition": "Given name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.first"
}
]
},
{
"id": "oidc-token.middle-name",
"path": "oidc-token.middle_name",
"short": "Middle name(s)",
"definition": "Middle name(s)",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.middle"
}
]
},
{
"id": "oidc-token.family-name",
"path": "oidc-token.family_name",
"short": "Family name",
"definition": "Family name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.last"
}
]
},
{
"id": "oidc-token.nickname",
"path": "oidc-token.nickname",
"short": "Casual name",
"definition": "Casual name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.preferred-username",
"path": "oidc-token.preferred_username",
"short": "Preferred username",
"definition": "Preferred username",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.profile",
"path": "oidc-token.profile",
"short": "Profile page URL",
"definition": "Profile page URL",
"min": 0,
"max": "1",
"type": [
{
"code": "uri"
}
]
},
{
"id": "oidc-token.picture",
"path": "oidc-token.picture",
"short": "Profile picture URL",
"definition": "Profile picture URL",
"min": 0,
"max": "1",
"type": [
{
"code": "uri"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.photo.url",
"comment": "Convert the URI to an Attachment URL."
}
]
},
{
"id": "oidc-token.website",
"path": "oidc-token.website",
"short": "Web page URL",
"definition": "Web page URL",
"min": 0,
"max": "1",
"type": [
{
"code": "uri"
}
]
},
{
"id": "oidc-token.email",
"path": "oidc-token.email",
"short": "Email address",
"definition": "Email address",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.emails.address"
}
]
},
{
"id": "oidc-token.email-verified",
"path": "oidc-token.email_verified",
"short": "Whether the email address was verified",
"definition": "Whether the email address was verified",
"min": 0,
"max": "1",
"type": [
{
"code": "boolean"
}
]
},
{
"id": "oidc-token.gender",
"path": "oidc-token.gender",
"short": "Gender",
"definition": "Gender",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.gender"
}
]
},
{
"id": "oidc-token.birthdate",
"path": "oidc-token.birthdate",
"short": "Birth date",
"definition": "Birth date",
"min": 0,
"max": "1",
"type": [
{
"code": "date"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.birthDate"
}
]
},
{
"id": "oidc-token.zoneinfo",
"path": "oidc-token.zoneinfo",
"short": "Time zone",
"definition": "Time zone",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.locale",
"path": "oidc-token.locale",
"short": "Locale",
"definition": "Locale",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.phone-number",
"path": "oidc-token.phone_number",
"short": "Phone number",
"definition": "Phone number",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.phoneNumbers.number"
}
]
},
{
"id": "oidc-token.phone-number-verified",
"path": "oidc-token.phone_number_verified",
"short": "Whether the phone number was verified",
"definition": "Whether the phone number was verified",
"min": 0,
"max": "1",
"type": [
{
"code": "boolean"
}
]
},
{
"id": "oidc-token.address",
"path": "oidc-token.address",
"short": "Postal address",
"definition": "Postal address",
"min": 0,
"max": "1",
"type": [
{
"code": "BackboneElement"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses",
"comment": "OIDC carries one address object; IdentityAssertion permits multiple addresses."
}
]
},
{
"id": "oidc-token.address.formatted",
"path": "oidc-token.address.formatted",
"short": "Full formatted address",
"definition": "Full formatted address",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.address.street-address",
"path": "oidc-token.address.street_address",
"short": "Street address",
"definition": "Street address",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.line",
"comment": "Split into lines when needed."
}
]
},
{
"id": "oidc-token.address.locality",
"path": "oidc-token.address.locality",
"short": "City or locality",
"definition": "City or locality",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.city"
}
]
},
{
"id": "oidc-token.address.region",
"path": "oidc-token.address.region",
"short": "State, province, or region",
"definition": "State, province, or region",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.state"
}
]
},
{
"id": "oidc-token.address.postal-code",
"path": "oidc-token.address.postal_code",
"short": "Postal code",
"definition": "Postal code",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.postalCode"
}
]
},
{
"id": "oidc-token.address.country",
"path": "oidc-token.address.country",
"short": "Country",
"definition": "Country",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.addresses.country"
}
]
},
{
"id": "oidc-token.updated-at",
"path": "oidc-token.updated_at",
"short": "Time the end-user information was last updated as a JWT NumericDate",
"definition": "Time the end-user information was last updated as a JWT NumericDate",
"min": 0,
"max": "1",
"type": [
{
"code": "decimal"
}
]
},
{
"id": "oidc-token.verified-claims",
"path": "oidc-token.verified_claims",
"short": "Verified claims with their verification context",
"definition": "Verified claims with their verification context",
"min": 0,
"max": "*",
"type": [
{
"code": "BackboneElement"
}
]
},
{
"id": "oidc-token.verified-claims.verification",
"path": "oidc-token.verified_claims.verification",
"short": "Verification context",
"definition": "Verification context",
"min": 0,
"max": "1",
"type": [
{
"code": "BackboneElement"
}
]
},
{
"id": "oidc-token.verified-claims.verification.trust-framework",
"path": "oidc-token.verified_claims.verification.trust_framework",
"short": "Trust framework",
"definition": "Trust framework",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "oidc-token.verified-claims.verification.time",
"path": "oidc-token.verified_claims.verification.time",
"short": "Time of verification",
"definition": "Time of verification",
"min": 0,
"max": "1",
"type": [
{
"code": "dateTime"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.assuranceDate"
}
]
},
{
"id": "oidc-token.verified-claims.verification.assurance-level",
"path": "oidc-token.verified_claims.verification.assurance_level",
"short": "Assurance level",
"definition": "Assurance level",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.assuranceLevel"
}
]
},
{
"id": "oidc-token.verified-claims.claims",
"path": "oidc-token.verified_claims.claims",
"short": "Identity claims covered by the verification",
"definition": "Identity claims covered by the verification",
"min": 0,
"max": "1",
"type": [
{
"code": "BackboneElement"
}
]
},
{
"id": "oidc-token.verified-claims.claims.given-name",
"path": "oidc-token.verified_claims.claims.given_name",
"short": "Verified given name",
"definition": "Verified given name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.first",
"comment": "Prefer this verified value over given_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.middle-name",
"path": "oidc-token.verified_claims.claims.middle_name",
"short": "Verified middle name(s)",
"definition": "Verified middle name(s)",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.middle",
"comment": "Prefer this verified value over middle_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.family-name",
"path": "oidc-token.verified_claims.claims.family_name",
"short": "Verified family name",
"definition": "Verified family name",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.names.last",
"comment": "Prefer this verified value over family_name when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.birthdate",
"path": "oidc-token.verified_claims.claims.birthdate",
"short": "Verified birth date",
"definition": "Verified birth date",
"min": 0,
"max": "1",
"type": [
{
"code": "date"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.birthDate",
"comment": "Prefer this verified value over birthdate when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.email",
"path": "oidc-token.verified_claims.claims.email",
"short": "Verified email address",
"definition": "Verified email address",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.emails.address",
"comment": "Prefer this verified value over email when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.phone-number",
"path": "oidc-token.verified_claims.claims.phone_number",
"short": "Verified phone number",
"definition": "Verified phone number",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
],
"mapping": [
{
"identity": "oidc-token-to-identity-assertion",
"map": "IdentityAssertion.phoneNumbers.number",
"comment": "Prefer this verified value over phone_number when both are present."
}
]
},
{
"id": "oidc-token.verified-claims.claims.ssn-last4",
"path": "oidc-token.verified_claims.claims.ssn_last4",
"short": "Proposal-specific claim for the last four SSN digits",
"definition": "Proposal-specific claim for the last four SSN digits",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
}
]
}
}