Question
When a Nominated Representative authenticates and authorises data sharing on behalf of a business, does the authentication relate to the Nominated Representative user or the business?
Answer
The PI claims such as sub, given_name, and family_name are related to the authenticated end user - the nominated representative. PI claims (excluding sub) are only disclosed via the userinfo endpoint, not in tokens. See Tokens.
The Customer API data is related to the business. Resource IDs requiring ID Permanence are bound to the business, not to the nominated representative. In other words, the ID Permanence accountId for an account should be the same for all nominated representatives establishing consent on behalf of the same business consumer.
See also ID Permanence and PPID.
History
29 August 2025. Removed references to PI claims in tokens.
Nominated Representative token
Question
When a Nominated Representative gives consent, on behalf of a business account, should the tokens issued during authentication relate to the business account, or the Nominated Representative user?.
Answer
The PII claims, such as sub, given_name, and family_name, are related to the authenticated end user, that is, the nominated representative. The Customer API data is related to the business. The resource IDs are bound to the business, not to the nominated representative.
In other words, the accountId for account 12345 should be the same, regardless of the nominated representative establishing consent on behalf of the business. ID Permanence should follow the standards.
See:
Comments
0 comments
Please sign in to leave a comment.