Skip to content
Discussion options

You must be logged in to vote

Hello @tongium
Ory Kratos is the identity/ login server; Ory Hydra is still the OAuth2/OIDC provider. In that setup, nothing changes about how you control sub for OAuth2 clients.

Ory Hydra supports public and pairwise subject strategies, and you can override the obfuscated sub value per login by setting force_subject_identifier when you accept the login request in your login app. See: [Subject anonymization][Hydra accept login]

The acceptOAuth2LoginRequest payload still has force_subject_identifier exactly for this use case; you can compute it dynamically based on the OAuth2 client and the authenticated Kratos identity. See: [Hydra accept login]

So if you migrate your IdP to Ory Kratos bu…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@tongium
Comment options

Answer selected by tongium
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants