UserInfo endpoint
Retrieve the authenticated subject’s permitted OpenID Connect claims.
Available in sandboxProduction approval required
Standards
OAuth 2.0 + OpenID Connect
Security
Authorization Code + PKCE
Healthcare identity
France + Luxembourg
Access
Sandbox public · production approved
Overview
Mediloop Identity provides a standards-based boundary for authentication and authorization. Public developers can build and test in sandbox; production access is controlled.
Request
Example
POST /oauth/userinfo
Authorization: Bearer $ACCESS_TOKEN
Content-Type: application/x-www-form-urlencodedParameters
| Parameter | Required | Description |
|---|---|---|
| client_id | Yes | Registered sandbox or approved production application |
| redirect_uri | Flow dependent | Must exactly match a registered redirect URI |
| scope | Yes | Request only the minimum approved scopes |
| state / nonce | Recommended | Protect flow integrity and bind the response |
Response
Illustrative response
{
"sub": "usr_...",
"iss": "https://identity.mediloop.com",
"aud": "$CLIENT_ID",
"scope": "openid profile"
}Security notes
Use least-privilege scopes, exact redirect URI matching, PKCE for public clients, short-lived access tokens and secure server-side storage for confidential credentials. Do not infer authorization from identity claims alone.
Errors
| Error | Meaning |
|---|---|
| invalid_request | Malformed or incomplete protocol request |
| invalid_client | Client authentication or registration failed |
| invalid_grant | Authorization grant is invalid or expired |
| access_denied | User, policy or approval denied access |