[midPoint] OIDC authentication - Matching users by an attribute other than 'name'

Lothar Haeger lothar.haeger at is4it.de
Thu Jun 25 14:49:07 CEST 2026



> Am 25.06.2026 um 14:26 schrieb Gianluca Bisi <gbisi at rakkau.com>:
> 
> We would like to know if it is possible to use a different midPoint attribute for OIDC authentication instead of the default name field.

I do not think that is possible right now. 

But if your Midpoint instance provisions Keycloak, you might be able to write the focus name to a custom Keycloak attribute, map that to a token claim in Keycloak and use <nameOfUsernameAttribute>… in the Midpoint auth config to use that claim instead of preferred_username… have not tried it yet, it's on the list, though.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/713d1e6e/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3779 bytes
Desc: not available
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/713d1e6e/attachment.bin>


More information about the midPoint mailing list