The CERN token claims

The semantics, straight from the service docs: cern_upn is unique (unique, not documented as immutable); sub duplicates it for generic OIDC clients; preferred_username is display-only and must never be used as an identifier; resource_access is an object keyed by application carrying the roles — scoped to the requesting client_id — and cern_roles is its flat duplicate.


Topology