すべてのプロダクト
Search
ドキュメントセンター

Identity as a Service:OIDC id_token のカスタムフィールド設定

最終更新日:Aug 18, 2026

このドキュメントでは、OIDC の id_token にカスタムフィールドを追加する方法と設定例について説明します。

id_token カスタムフィールドのルール

id_token のカスタムフィールドの値には、変数、定数、または式を指定できます。変数の場合は、変数名を引用符なしで直接入力します。定数値の場合は、二重引用符 ("") で囲みます。

タイプ

値

説明

変数

変数名を直接入力します。引用符は不要です。

user.username

ユーザー名です。

user.displayName

表示名です。

user.phone (非推奨)

国コードを含まない電話番号です。この変数は非推奨です。

user.phoneNumber

国コードを含まない電話番号です。

user.email

ユーザーのメールアドレスです。

user.status

ユーザーのステータスです。有効な値:

  • enabled:ユーザーが有効な状態です。

  • disabled:ユーザーが無効な状態です。

user.primaryOrganizationalUnitId

ユーザーのプライマリ組織単位の ID です。

user.organizationalUnits

ユーザーが所属する組織単位です。

ArrayMap(user.organizationalUnits, __item.organizationalUnitId)

ユーザーが所属する組織単位の ID です。

フォーマット:JSON 配列。

user.groups

ユーザーアカウントが所属するグループです。

フォーマット:JSON 配列。

ArrayMap(user.groups, __item.groupId)

ユーザーのグループ ID です。

フォーマット:JSON 配列。

ArrayMap(user.groups, __item.groupExternalId)

ユーザーの外部グループ ID です。

フォーマット:JSON 配列。

user.customFields

ユーザーのカスタムフィールドです。

フォーマット:JSON 配列。

user.customFieldMap.$fieldname$.fieldValue

特定のカスタムフィールドの値です。$fieldname$ をカスタムフィールドの名前に置き換えます。

定数

固定の文字列値です。定数を二重引用符 ("") で囲みます。

式

値を連結または変換するための高度な機能です。

詳細については、「Advanced account field expressions」をご参照ください。

ユーザーオブジェクトの例:

{
  ...
  "customFieldMap": {
        "place": {
            "fieldName": "place",
            "fieldValue": "beijing"
        },
        "age": {
            "fieldName": "age",
            "fieldValue": "18"
        }
    },
    "identityProviderUserMap": {
        "idp_m2gngriuenktdkxxxxxx": {
            "identityProviderId": "idp_m2gngriuenktdkxxxxxx",
            "identityProviderType": "ding_talk",
            "identityProviderExternalId": "corp_1234xxxxxxx",
            "identityProviderUserId": "b2ed5fc0xxxxx"
        }
    },
    "organizationalUnits": [
        {
            "organizationalUnitId": "ou_sdfadtaaxxxxxx",
            "organizationalUnitName": "AD",
            "primary": false
        },
        {
            "organizationalUnitId": "ou_werttxxxxxx",
            "organizationalUnitName": "name_002",
            "primary": true
        }
    ],
    "primaryOrganizationalUnitId": "ou_werttxxxxxx",
    "customFields": [
        {
            "fieldName": "place",
            "fieldValue": "beijing"
        },
        {
            "fieldName": "age",
            "fieldValue": "18"
        }
    ],
    "groups": [
        {
            "groupId": "group_jp6al4sn4n4wjgjxxxxxx",
            "groupName": "group1",
            "groupExternalId": "group_jp6al4sn4n4wjgjxxxxxx"
        },
        {
            "groupId": "group_vavikcxewkf5h3oxxxxxx",
            "groupName": "group2",
            "groupExternalId": "group_vavikcxewkf5h3oxxxxxx"
        }
    ],
  ...
}

OIDC の式の例

IDaaS の [application] ページで、[Show advanced configuration] をクリックして詳細設定エリアを展開します。[Extend id_token] セクションで、カスタムフィールド名とそれに対応する式をマッピングテーブルに追加します。

  1. 式 user.organizationalUnits は、以下を返します:

    [
      {
        "organizationalUnitId": "ou_sdfadtaaxxxxxx",
        "organizationalUnitName": "AD",
        "primary": false
      },
      {
        "organizationalUnitId": "ou_werttxxxxxx",
        "organizationalUnitName": "name_002",
        "primary": true
      }
    ]
  2. 式 ArrayMap(user.organizationalUnits, __item.organizationalUnitId) は、以下を返します:

    [
      "ou_sdfadtaaxxxxxx",
      "ou_werttxxxxxx"
    ]
  3. 式 user.groups は、以下を返します:

    [
      {
        "groupId": "group_jp6al4sn4n4wjgjxxxxxx",
        "groupName": "group1",
        "groupExternalId": "group_jp6al4sn4n4wjgjxxxxxx"
      },
      {
        "groupId": "group_vavikcxewkf5h3oxxxxxx",
        "groupName": "group2",
        "groupExternalId": "group_vavikcxewkf5h3oxxxxxx"
      }
    ]
  4. 式 ArrayMap(user.groups, __item.groupId) は、以下を返します:

    [
        "group_jp6al4sn4n4wjgjxxxxxx",
        "group_vavikcxewkf5h3oxxxxxx"
    ]
  5. 式 ArrayMap(user.groups, __item.groupExternalId) は、以下を返します:

    [
        "group_jp6al4sn4n4wjgjxxxxxx",
        "group_vavikcxewkf5h3oxxxxxx"
    ]
  6. 式 user.customFields は、以下を返します:

    [
        {
          "fieldName": "place",
          "fieldValue": "beijing"
        },
        {
          "fieldName": "age",
          "fieldValue": "18"
        }
    ]
  7. 式 user.customFieldMap.age.fieldValue は、以下を返します:

    18

id_token カスタムフィールドの書き換えルール

デフォルトフィールドのルール

  1. システムのデフォルトフィールドは書き換えできません:exp、nbf、iat、iss、jti、at_hash、c_hash、nonce、sid。

  2. フィールドの書き換えをサポートします:sub。

ユーザー情報フィールドのルール

id_token 内の以下のユーザー情報フィールドを書き換えできるかどうかは、リクエストされた scope によって決まります。

フィールド名

関連スコープ

書き換え不可の条件

email、email_verified

email

リクエストされた scope に email が含まれ、かつユーザーの email 属性が空でない場合。

phone_number、phone_number_verified

phone

リクエストされた scope に phone が含まれ、かつユーザーの phoneNumber 属性が空でない場合。

name、preferred_username、updated_at、locale

profile

リクエストされた scope に profile が含まれる場合。

instance_id、application_id

instance

リクエストされた scope に instance が含まれる場合。

設定の推奨事項

  1. アプリケーションの設定でスコープを慎重に選択してください。リクエストするスコープによって、どのユーザーフィールドが書き換え可能かが決まります。

  2. 特定のフィールドを書き換えるには、関連する scope がリクエストされていないこと、または対応するユーザー属性が空であることを確認してください。