[midPoint] OIDC authentication - Matching users by an attribute other than 'name'
Gianluca Bisi
gbisi at rakkau.com
Thu Jun 25 14:26:09 CEST 2026
Hi everyone,
Lothar is correct. The attribute or claim selected in
nameOfUsernameAttribute must match the name attribute of the user in
midPoint.
In our case, even though we receive the email within the claims, the user
has a different identifier configured as the name in midPoint, which
prevents the authentication from working correctly under this configuration.
We would like to know if it is possible to use a different midPoint
attribute for OIDC authentication instead of the default name field.
Best regards,
*Gianluca Bisi*
Developer | Rakkau
gbisi at rakkau.com
www.rakkau.com
El jue, 25 jun 2026 a la(s) 7:40 a.m., Lothar Haeger via midPoint (
midpoint at lists.evolveum.com) escribió:
>
> Am 25.06.2026 um 10:55 schrieb Markus Calmius via midPoint <
> midpoint at lists.evolveum.com>:
>
> our keycloak config contains this:
> <nameOfUsernameAttribute>email</nameOfUsernameAttribute>
>
>
> I ran into the same question as Gianluca and my understanding is that
> <nameOfUsernameAttribute>email</nameOfUsernameAttribute> means: "read the
> email claim from Keycloak, then look up the midPoint user whose name equals
> that email." If name isn't the email, it matches nobody. It does not search
> against an "email" property in midPoint.
> _______________________________________________
> midPoint mailing list
> midPoint at lists.evolveum.com
> https://lists.evolveum.com/mailman/listinfo/midpoint
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/c36a7904/attachment.htm>
More information about the midPoint
mailing list