3 ms·
I think the key point is that by design, OpenID Connect doesn't necessitate that the identity provider reveals the users email address to the service provider.
by cdcarter 10y ago
I think the key point is that by design, OpenID Connect doesn't necessitate that the identity provider reveals the users email address to the service provider. The identity provider can choose to include that in the token (or the UserInfo endpoint) or they can hide it behind another OAuth scope and explicit permission.
Whereas by design, Persona does mean the service provider has access to your email address. For consumer applications, this is probably fine, but it's a very different assumption than most access and authorization use.