OpenID Connect Specification Change: Truncation of the iss Field
Breaking Change: iss field in id_token format update - Oracle
Oracle announced a breaking change concerning the format of the 'iss' field within the id_token.
Summary
Oracle announced a technical change to truncate the issuer (iss) field in OpenID Connect identity tokens (id_token). This is necessary for compliance with SMART App Launch specifications and aligns with regulatory requirements, requiring developers to update their code and configurations.
Details
Oracle has announced a mandatory specification change on its Authorization Server. To achieve full compliance with version 2.0 of the SMART App Launch specification, they will be truncating the contents of the issuer (iss) field within OpenID Connect identity tokens (id_token). This technical update is driven by the need to meet regulatory requirements, specifically the HTI-1 Final Rule under the 21st Century Cures Act in the United States. Developers utilizing OpenID Connect must be aware that their applications will require code and/or configuration changes. The change affects only applications requesting SMART's "openid" scope for identity tokens. Oracle provided a phased rollout schedule, starting with developer sandbox environments in 2025. This mandatory update is critical for maintaining interoperability compliance within the US healthcare ecosystem. Developers should consult relevant technical documentation regarding OpenID Connect and HL7 standards to minimize disruption and ensure their applications can process both the old and new token formats.
Technology Note
FHIR(Fast Healthcare Interoperability Resources)は医療データ交換の国際標準。このエントリの関連技術: FHIR
Original content copyright by respective publishers