4 ms·
It's mostly compliant as of a few months ago [0]. That document is actually out of date, because Apple added a discovery endpoint since then [1]. They also have
by TJSomething 7y ago
It's mostly compliant as of a few months ago [0]. That document is actually out of date, because Apple added a discovery endpoint since then [1]. They also haven't implemented the userinfo endpoint, but the only claims they expose are openid, name, and email, so it's not that big of a deal to just ask for those in the id_token. And the client_secret_post thing isn't much of a problem either, since their custom JWT is a perfectly valid client secret that's compliant with the underlying OAuth 2.0 standard and it's explained in their discovery document.
[0] https://bitbucket.org/openid/connect/src/default/How-Sign-in-with-Apple-differs-from-OpenID-Connect.md https://bitbucket.org/openid/connect/src/default/How-Sign-in...
[1] https://appleid.apple.com/.well-known/openid-configuration https://appleid.apple.com/.well-known/openid-configuration