Meaning of Public Identifier for OIDC Client IDs in Okta
Last Updated:
Overview
Okta describes an OpenID Connect (OIDC) Client ID as a public identifier because it is not a secret credential. However, public does not mean publicly searchable, and Okta documentation does not identify a mechanism that publicly lists or enumerates customer-created OIDC Client IDs.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect (OIDC)
- OAuth 2.0
Solution
A Public OIDC Client ID Is Not a Secret Credential
A Client ID identifies an application during OAuth and OIDC requests, so it can appear in normal protocol requests. This does not mean that Okta publishes the Client ID in a searchable directory.
Does Okta publicly list or enumerate OIDC Client IDs?
Okta documentation does not identify a mechanism that publicly lists or enumerates customer-created OIDC Client IDs for someone who does not already know the Client ID.
In simple terms, a Client ID can be public without being publicly searchable.
