Skip to content

Supported mapping from OIDC sub to Person.id #1496

Description

@cusxio

Related Product

API / People / Groups / OpenID Connect

Describe the question

We authenticate users through Planning Center OIDC, then use a dedicated server-side PAT to check their People status and Groups memberships.

OIDC provides iss, sub, and organization_id, while the People and Groups APIs identify a person using Person.id. We do not want to assume that a numeric-looking sub equals Person.id or use email as the identity join.

Could you clarify:

  1. Is OIDC sub contractually equal to a People or Groups Person.id?
  2. If not, can a PAT resolve (iss, sub, organization_id) to a Person.id?
  3. Otherwise, is the supported approach to call /people/v2/me with the user's OAuth token, store its Person.id, discard the token, and use the PAT for later checks?
  4. What scopes and minimum permissions does /people/v2/me require?

We reviewed #278, #766, #1271, and #1397, but none appears to define this mapping.

What have you tried that worked?

OIDC returns sub and organization_id; /people/v2/me returns the current OAuth user's Person resource.

What have you tried that didn't work?

We found no documented mapping from OIDC sub to Person.id.

I have..

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions