<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell) in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/ta-p/1843408</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;This article explains how to request a token manually from your Identity provider token endpoint and verify if the required attributes are included in the id_token.&lt;/P&gt;
&lt;P&gt;Qlik Sense Enterprise for Windows reads the attributes from the id_token and is not using the /userinfo endpoint to fetch them.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environments:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; May 2021 and higher&lt;BR /&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise SaaS" id="qlikSenseEnterpriseSaaS"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;(For "ADFS" and "Azure" Identity provider types only)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, for testing purposes, add the URL "&lt;A href="https://test/login/callback&amp;quot;" target="_blank" rel="noopener"&gt;https://test/login/callback"&lt;/A&gt;&amp;nbsp;used in this script in your Identity Provider (IdP) allowed redirect URIs. The reason we are doing this is because we want to request the token manually to check its content and not have it getting automatically processed by Qlik Sense.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Run the below PowerShell script to get your authorization URL. Variables authorization_endpoint, client_id, and scope need to be updated to match your IdP, those information can be found from the /.well-known/openid-configuration endpoint.&lt;BR /&gt;&lt;LI-CODE lang="cpp"&gt;$authorization_endpoint = 'https://dc1.domain.local/adfs/oauth2/authorize'
$client_id = '592a5672-a360-49da-93a4-20654f42d3c2'
$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")
#For ADFS, use 'openid%20allatclaims%20profile%20email' for the scope
$scope = 'openid%20profile%20email'
$code_challenge="7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8"

#Paste this URL in your browser to get back the authorization code
$authorization_endpoint+'?response_type=code&amp;amp;client_id='+$client_id+'&amp;amp;redirect_uri='+$redirect_uri+'&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kjikCWCxqzxOx007aXbKMUd0YXBwA3sUk&amp;amp;scope='+$scope+'&amp;amp;code_challenge_method=S256&amp;amp;code_challenge='+$code_challenge&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Paste the URL output from the script in your browser and log in to your Identity provider, the URL should look like this:&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;https://dc1.domain.local/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=592a5672-a360-49da-93a4-20654f42d3c2&amp;amp;redirect_uri=https%3a%
2f%2ftest%2flogin%2fcallback&amp;amp;state=xyzABC123
&amp;amp;scope=openid%20allatclaims%20profile%20email​&lt;/LI-CODE&gt;&lt;BR /&gt;After the authentication is completed, you will be redirected to&amp;nbsp;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://test/login/callback&amp;quot;" target="_blank" rel="noopener"&gt;https://test/login/callback&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;with an authorization code in the URL, copy the &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;authorization code&lt;/STRONG&gt;&lt;SPAN&gt; that we will use in the next step.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Copy the value between code= and the next &amp;amp; sign. (The length of the authorization code may vary depending on the IdP)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1633594363132.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/63624iC07FE84101AD151A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1633594363132.png" alt="Damien_Villaret_0-1633594363132.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Request the token from the token_endpoint URL (also found from&amp;nbsp;the /.well-known/openid-configuration endpoint)&lt;BR /&gt;&lt;LI-CODE lang="cpp"&gt;$client_id = '592a5672-a360-49da-93a4-20654f42d3c2'
$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")
$client_secret = 'Ssxx92jvm6RE_Plf1NnKgduZujE99nd0vWuujE_L'
$token_endpoint = 'https://dc1.domain.local/adfs/oauth2/token'
$code_verifier="_fqY.Xg5srawq24h9_A57tjY-ycqX0PzzIcM7VcwLZRou_Mvqn-_tCTz4ICWcXoCTO8NXlm3b9RfGOjSZEH68a_gWgaLByddN5y52M06~Z8XlO3XMgOJRWK0DefsxcmC"

#Put your authorization code here
$auth_code = 'mSzqI71WMUGuYcxSTciAcw.kZdiCG6J2QgNAPRcEZ9A51OMW6g.TMrNMhHPBiG3aNbh_4lbUakFzWoU_MFcDQZcL6_wBIaDd_1_DMWz9OZUSvRcE_zR115HwNXdZYUTjHB6mcnK3u5R2EDxsVKthwQwbP184ujVK1c8LmI-QOMb4jEGRTAm49nbtM8MfO4pTO1fICMSU7CLuhVb8KcCefjPOQ5W0JMKLl7XElvhJDLg5n6v1V2m8L2ZaCQVDy6oTiZygIr20j3TpQnpu2Zwk1KzbttOTGqeJgzCoyPJJJcRjnOrD1zPmBEENrz8fuZwdihRIPZufzhj0gEJ18-stWBz7polztBH7y_jKn-mK6WgIqlLSG2AlmcQa9kBANLmfbal7OUFtA'
$pair = "$($client_id):$($client_secret)"
$encodedCreds = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes($pair))
$basicAuthValue = "Basic $encodedCreds"

$hdrs = @{}
$hdrs.Add("Authorization",$basicAuthValue)
$body = 'code='+$auth_code+'&amp;amp;grant_type=authorization_code&amp;amp;redirect_uri='+$redirect_uri+'&amp;amp;code_verifier='+$code_verifier

$response = Invoke-WebRequest -Uri $token_endpoint -Method Post -Body $body -Headers $hdrs -ContentType 'application/x-www-form-urlencoded'
echo $response.Content​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Copy the value in "id_token" from the request response, and decode the JWT token to see what it contains.&lt;BR /&gt;&lt;BR /&gt;For simplicity, you can use the debugger on &lt;A style="font-family: inherit; background-color: #ffffff;" href="https://jwt.io" target="_blank" rel="noopener"&gt;https://jwt.io :&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1633596284198.png" style="width: 745px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/63625iB135B8F2189CF423/image-dimensions/745x551?v=v2" width="745" height="551" role="button" title="Damien_Villaret_1-1633596284198.png" alt="Damien_Villaret_1-1633596284198.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;You can confirm if the expected claims are included in the token payload or not.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 10 May 2022 17:43:00 GMT</pubDate>
    <dc:creator>Damien_V</dc:creator>
    <dc:date>2022-05-10T17:43:00Z</dc:date>
    <item>
      <title>Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/ta-p/1843408</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;This article explains how to request a token manually from your Identity provider token endpoint and verify if the required attributes are included in the id_token.&lt;/P&gt;
&lt;P&gt;Qlik Sense Enterprise for Windows reads the attributes from the id_token and is not using the /userinfo endpoint to fetch them.&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environments:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; May 2021 and higher&lt;BR /&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise SaaS" id="qlikSenseEnterpriseSaaS"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;(For "ADFS" and "Azure" Identity provider types only)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, for testing purposes, add the URL "&lt;A href="https://test/login/callback&amp;quot;" target="_blank" rel="noopener"&gt;https://test/login/callback"&lt;/A&gt;&amp;nbsp;used in this script in your Identity Provider (IdP) allowed redirect URIs. The reason we are doing this is because we want to request the token manually to check its content and not have it getting automatically processed by Qlik Sense.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Run the below PowerShell script to get your authorization URL. Variables authorization_endpoint, client_id, and scope need to be updated to match your IdP, those information can be found from the /.well-known/openid-configuration endpoint.&lt;BR /&gt;&lt;LI-CODE lang="cpp"&gt;$authorization_endpoint = 'https://dc1.domain.local/adfs/oauth2/authorize'
$client_id = '592a5672-a360-49da-93a4-20654f42d3c2'
$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")
#For ADFS, use 'openid%20allatclaims%20profile%20email' for the scope
$scope = 'openid%20profile%20email'
$code_challenge="7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8"

#Paste this URL in your browser to get back the authorization code
$authorization_endpoint+'?response_type=code&amp;amp;client_id='+$client_id+'&amp;amp;redirect_uri='+$redirect_uri+'&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kjikCWCxqzxOx007aXbKMUd0YXBwA3sUk&amp;amp;scope='+$scope+'&amp;amp;code_challenge_method=S256&amp;amp;code_challenge='+$code_challenge&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Paste the URL output from the script in your browser and log in to your Identity provider, the URL should look like this:&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;https://dc1.domain.local/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=592a5672-a360-49da-93a4-20654f42d3c2&amp;amp;redirect_uri=https%3a%
2f%2ftest%2flogin%2fcallback&amp;amp;state=xyzABC123
&amp;amp;scope=openid%20allatclaims%20profile%20email​&lt;/LI-CODE&gt;&lt;BR /&gt;After the authentication is completed, you will be redirected to&amp;nbsp;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://test/login/callback&amp;quot;" target="_blank" rel="noopener"&gt;https://test/login/callback&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;with an authorization code in the URL, copy the &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;authorization code&lt;/STRONG&gt;&lt;SPAN&gt; that we will use in the next step.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Copy the value between code= and the next &amp;amp; sign. (The length of the authorization code may vary depending on the IdP)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1633594363132.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/63624iC07FE84101AD151A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1633594363132.png" alt="Damien_Villaret_0-1633594363132.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Request the token from the token_endpoint URL (also found from&amp;nbsp;the /.well-known/openid-configuration endpoint)&lt;BR /&gt;&lt;LI-CODE lang="cpp"&gt;$client_id = '592a5672-a360-49da-93a4-20654f42d3c2'
$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")
$client_secret = 'Ssxx92jvm6RE_Plf1NnKgduZujE99nd0vWuujE_L'
$token_endpoint = 'https://dc1.domain.local/adfs/oauth2/token'
$code_verifier="_fqY.Xg5srawq24h9_A57tjY-ycqX0PzzIcM7VcwLZRou_Mvqn-_tCTz4ICWcXoCTO8NXlm3b9RfGOjSZEH68a_gWgaLByddN5y52M06~Z8XlO3XMgOJRWK0DefsxcmC"

#Put your authorization code here
$auth_code = 'mSzqI71WMUGuYcxSTciAcw.kZdiCG6J2QgNAPRcEZ9A51OMW6g.TMrNMhHPBiG3aNbh_4lbUakFzWoU_MFcDQZcL6_wBIaDd_1_DMWz9OZUSvRcE_zR115HwNXdZYUTjHB6mcnK3u5R2EDxsVKthwQwbP184ujVK1c8LmI-QOMb4jEGRTAm49nbtM8MfO4pTO1fICMSU7CLuhVb8KcCefjPOQ5W0JMKLl7XElvhJDLg5n6v1V2m8L2ZaCQVDy6oTiZygIr20j3TpQnpu2Zwk1KzbttOTGqeJgzCoyPJJJcRjnOrD1zPmBEENrz8fuZwdihRIPZufzhj0gEJ18-stWBz7polztBH7y_jKn-mK6WgIqlLSG2AlmcQa9kBANLmfbal7OUFtA'
$pair = "$($client_id):$($client_secret)"
$encodedCreds = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes($pair))
$basicAuthValue = "Basic $encodedCreds"

$hdrs = @{}
$hdrs.Add("Authorization",$basicAuthValue)
$body = 'code='+$auth_code+'&amp;amp;grant_type=authorization_code&amp;amp;redirect_uri='+$redirect_uri+'&amp;amp;code_verifier='+$code_verifier

$response = Invoke-WebRequest -Uri $token_endpoint -Method Post -Body $body -Headers $hdrs -ContentType 'application/x-www-form-urlencoded'
echo $response.Content​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Copy the value in "id_token" from the request response, and decode the JWT token to see what it contains.&lt;BR /&gt;&lt;BR /&gt;For simplicity, you can use the debugger on &lt;A style="font-family: inherit; background-color: #ffffff;" href="https://jwt.io" target="_blank" rel="noopener"&gt;https://jwt.io :&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1633596284198.png" style="width: 745px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/63625iB135B8F2189CF423/image-dimensions/745x551?v=v2" width="745" height="551" role="button" title="Damien_Villaret_1-1633596284198.png" alt="Damien_Villaret_1-1633596284198.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;You can confirm if the expected claims are included in the token payload or not.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 May 2022 17:43:00 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/ta-p/1843408</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2022-05-10T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861084#M4850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/29425"&gt;@Damien_V&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please clarify the importance of this parameter and where we can take this from?&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;$code_challenge&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Because I am having issues like below&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockabs_0-1637248807788.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/66977iBA4BBFA876CBD6C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockabs_0-1637248807788.png" alt="rockabs_0-1637248807788.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:20:14 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861084#M4850</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-18T15:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861095#M4852</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/91754"&gt;@rockabs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error message relates to redirect_uri. Did you change this line in the script to anything else? You don't need to change the line, but you should add &lt;A href="https://test/login/callback" target="_blank"&gt;https://test/login/callback&lt;/A&gt;&amp;nbsp;in the list of allowed redirect_uri in your Identity Provider configuration.&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The code_challenge in this article is just a static one that matches base64(SHA256Hash(code_verifier)) value&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:38:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861095#M4852</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-18T15:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861097#M4853</link>
      <description>&lt;P&gt;Good, for Code_challenge. and the script, this is how I have with the same issue&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockabs_0-1637250083046.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/66980i26AF973C2F9FE12A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockabs_0-1637250083046.png" alt="rockabs_0-1637250083046.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:41:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861097#M4853</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-18T15:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861098#M4854</link>
      <description>&lt;P&gt;Is the query string you get similar to the one shown in step 2 ?&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;https://dc1.domain.local/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=592a5672-a360-49da-93a4-20654f42d3c2&amp;amp;redirect_uri=https%3a%
2f%2ftest%2flogin%2fcallback&amp;amp;state=xyzABC123
&amp;amp;scope=openid%20allatclaims%20profile%20email​&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Which Identity Provider do you use ? and did you add the redirect_uri to the list of allowed redirect_uri in your Identity Provider configuration ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:45:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861098#M4854</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-18T15:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861105#M4855</link>
      <description>&lt;P&gt;This is how it is after&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;https://&lt;STRONG&gt;abc&lt;/STRONG&gt;.eu.auth0.com/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=&lt;STRONG&gt;xxx&lt;/STRONG&gt;&amp;amp;redirect_uri=&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kji&lt;BR /&gt;kCWCxqzxOx007aXbKMUd0YXBwA3sUk&amp;amp;scope=openid%20allatclaims%20profile%20email&amp;amp;code_challenge_method=S256&amp;amp;code_challenge=7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8&lt;/P&gt;
&lt;P&gt;About adding this&amp;nbsp;&lt;A href="https://test/login/callback" target="_blank"&gt;https://test/login/callback&lt;/A&gt;&amp;nbsp;to be list, I will check internally and get back!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:53:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861105#M4855</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-18T15:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861394#M4860</link>
      <description>&lt;P&gt;I have added the list to IDP, Still, the issue is there. I have a configuration like below, To know these diagnostics/token attributes I was looking for this solution to apply.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockabs_0-1637319427123.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/67026iFC0BC92A81E5975C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockabs_0-1637319427123.png" alt="rockabs_0-1637319427123.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 10:57:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861394#M4860</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-19T10:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861401#M4862</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/91754"&gt;@rockabs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't have any redirect_uri in the URL you've sent.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://&lt;/SPAN&gt;&lt;STRONG&gt;abc&lt;/STRONG&gt;&lt;SPAN&gt;.eu.auth0.com/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=&lt;/SPAN&gt;&lt;STRONG&gt;xxx&lt;/STRONG&gt;&lt;SPAN&gt;&amp;amp;redirect_uri=&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kji&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kCWCxqzxOx007aXbKMUd0YXBwA3sUk&amp;amp;scope=openid%20allatclaims%20profile%20email&amp;amp;code_challenge_method=S256&amp;amp;code_challenge=7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There should be "https%3A%2F%2Ftest%2Flogin%2Fcallback" just after &amp;amp;redirect_uri=&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://&lt;STRONG&gt;abc&lt;/STRONG&gt;.eu.auth0.com/adfs/oauth2/authorize?response_type=code&amp;amp;client_id=&lt;STRONG&gt;xxx&lt;/STRONG&gt;&amp;amp;redirect_uri=&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;https%3A%2F%2Ftest%2Flogin%2Fcallback&lt;/STRONG&gt;&lt;/FONT&gt;&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kji&lt;BR /&gt;kCWCxqzxOx007aXbKMUd0YXBwA3sUk&amp;amp;scope=openid%20allatclaims%20profile%20email&amp;amp;code_challenge_method=S256&amp;amp;code_challenge=7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 11:10:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861401#M4862</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-19T11:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861420#M4864</link>
      <description>&lt;P&gt;I managed with another way account where that works. Now I am here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockabs_0-1637323192589.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/67032i342964AC9E76053C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockabs_0-1637323192589.png" alt="rockabs_0-1637323192589.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://abc-icow-test.eu.auth0.com/authorize?response_type=code&amp;amp;client_id=xxx&amp;amp;redirect_uri=https%3A%2F%2Ftest%2Flogin%2Fcallback&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kjikCWCxqzxOx00" target="_blank"&gt;https://abc-icow-test.eu.auth0.com/authorize?response_type=code&amp;amp;client_id=xxx&amp;amp;redirect_uri=https%3A%2F%2Ftest%2Flogin%2Fcallback&amp;amp;state=xyzABC123&amp;amp;nonce=3O2bsVV99-kjikCWCxqzxOx00&lt;/A&gt;&lt;BR /&gt;7aXbKMUd0YXBwA3sUk&amp;amp;scope=openid%20allatclaims%20profile%20email&amp;amp;code_challenge_method=S256&amp;amp;code_challenge=7TsROgPKuP0hHoWWwEGqMsIOgzokT3xAz8kWoo7Ivp8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 12:00:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861420#M4864</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-19T12:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861426#M4865</link>
      <description>&lt;P&gt;It's normal that &lt;A href="https://test/login/callback" target="_blank"&gt;https://test/login/callback&lt;/A&gt;&amp;nbsp;doesnt open, it's just a dummy URL, however you should now have a code in the URL that you can copy and use in step 3 to get the token.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 12:14:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861426#M4865</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-19T12:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861430#M4866</link>
      <description>&lt;P&gt;We are close now, I see the URL is like this. and I have taken the bold part to this parameter "$auth_code".&lt;/P&gt;
&lt;P&gt;&lt;A href="https://test/login/callback?code=" target="_blank"&gt;https://test/login/callback?code=&lt;/A&gt;&lt;STRONG&gt;vT1neefRlijhMOjIrWdVJkL-E7Nv4xHrRyKuJwvAE6SP7&lt;/STRONG&gt;&amp;amp;state=xyzABC123#&lt;/P&gt;
&lt;P&gt;Now, I got the error below one?&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;FONT color="#FF0000"&gt;Unable to find type [System.Web.HTTPUtility].&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;At C:\Users\ansam3\Documents\Untitled1.ps1:2 char:17&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ $redirect_uri = [System.Web.HTTPUtility]::UrlEncode("&lt;A href="https://test/log" target="_blank"&gt;https://test/log&lt;/A&gt; ...&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ ~~~~~~~~~~~~~~~~~~~~~~~~&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ CategoryInfo : InvalidOperation: (System.Web.HTTPUtility:TypeName) [], RuntimeException&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ FullyQualifiedErrorId : TypeNotFound&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Invoke-WebRequest : Not found.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;At C:\Users\ansam3\Documents\Untitled1.ps1:17 char:13&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ $response = Invoke-WebRequest -Uri $token_endpoint -Method Post -Body ...&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;+ FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 19 Nov 2021 12:25:24 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861430#M4866</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-19T12:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861438#M4868</link>
      <description>&lt;P&gt;I think it's because of your PowerShell version.&lt;/P&gt;
&lt;P&gt;Try to replace the line&lt;/P&gt;
&lt;LI-CODE lang="cpp"&gt;$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("https://test/login/callback")&lt;/LI-CODE&gt;
&lt;P&gt;by&lt;/P&gt;
&lt;LI-CODE lang="cpp"&gt;$redirect_uri = "https%3A%2F%2Ftest%2Flogin%2Fcallback"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and try again (Make sure to generate a new code as the old one may already be invalid now)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 12:36:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861438#M4868</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-19T12:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861511#M4870</link>
      <description>&lt;P&gt;It seems It didn't help&lt;/P&gt;
&lt;P&gt;Invoke-WebRequest : Not found.&lt;BR /&gt;At C:\Users\ansam3\Documents\Untitled1.ps1:18 char:13&lt;BR /&gt;+ $response = Invoke-WebRequest -Uri $token_endpoint -Method Post -Body ...&lt;BR /&gt;+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;BR /&gt;+ CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException&lt;BR /&gt;+ FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:36:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861511#M4870</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-19T14:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861516#M4871</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/91754"&gt;@rockabs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you update all variables correctly ?&lt;/P&gt;
&lt;P&gt;What is your token endpoint set to ?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:40:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861516#M4871</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-19T14:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861517#M4872</link>
      <description>&lt;P&gt;Here is the one,&lt;/P&gt;
&lt;P&gt;$token_endpoint = 'https://&lt;STRONG&gt;abc&lt;/STRONG&gt;-icow-test.eu.auth0.com/.well-known/openid-configuration'&lt;/P&gt;
&lt;P&gt;And for ref, Script as follows&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;
&lt;P&gt;$client_id = 'xxx'&lt;BR /&gt;#$redirect_uri = [System.Web.HTTPUtility]::UrlEncode("&lt;A href="https://test/login/callback" target="_blank"&gt;https://test/login/callback&lt;/A&gt;")&lt;BR /&gt;$redirect_uri = "https%3A%2F%2Ftest%2Flogin%2Fcallback"&lt;BR /&gt;$client_secret = 'xxx'&lt;BR /&gt;$token_endpoint = '&lt;A href="https://abc-icow-test.eu.auth0.com/.well-known/openid-configuration" target="_blank"&gt;https://abc-icow-test.eu.auth0.com/.well-known/openid-configuration&lt;/A&gt;'&lt;BR /&gt;$code_verifier="_fqY.Xg5srawq24h9_A57tjY-ycqX0PzzIcM7VcwLZRou_Mvqn-_tCTz4ICWcXoCTO8NXlm3b9RfGOjSZEH68a_gWgaLByddN5y52M06~Z8XlO3XMgOJRWK0DefsxcmC"&lt;/P&gt;
&lt;P&gt;#Put your authorization code here&lt;BR /&gt;$auth_code = 'Z4SQMNz-bveDQoSqVhhGl10fMefWJy8gIl_Vu3m4wrlY'&lt;BR /&gt;$pair = "$($client_id):$($client_secret)"&lt;BR /&gt;$encodedCreds = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes($pair))&lt;BR /&gt;$basicAuthValue = "Basic $encodedCreds"&lt;/P&gt;
&lt;P&gt;$hdrs = @{}&lt;BR /&gt;$hdrs.Add("Authorization",$basicAuthValue)&lt;BR /&gt;$body = 'code='+$auth_code+'&amp;amp;grant_type=authorization_code&amp;amp;redirect_uri='+$redirect_uri+'&amp;amp;code_verifier='+$code_verifier&lt;/P&gt;
&lt;P&gt;$response = Invoke-WebRequest -Uri $token_endpoint -Method Post -Body $body -Headers $hdrs -ContentType 'application/x-www-form-urlencoded'&lt;BR /&gt;echo $response.Content​&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:43:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861517#M4872</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-19T14:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861522#M4873</link>
      <description>&lt;P&gt;This is not the correct token endpoint.&lt;/P&gt;
&lt;P&gt;You need to open&amp;nbsp;&lt;A href="https://abc-icow-test.eu.auth0.com/.well-known/openid-configuration" target="_blank" rel="nofollow noopener noreferrer"&gt;https://abc-icow-test.eu.auth0.com/.well-known/openid-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;in your browser and find the correct token endpoint, it should appear as token_endpoint in there.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:55:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1861522#M4873</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-19T14:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1862696#M4895</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/29425"&gt;@Damien_V&lt;/a&gt;&amp;nbsp;That is working, But, somehow still issue with 400. Any other clue, where I can think about?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rockabs_0-1637684066053.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/67280iEA82EB789ED94209/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rockabs_0-1637684066053.png" alt="rockabs_0-1637684066053.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 16:14:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1862696#M4895</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-23T16:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1862962#M4897</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/91754"&gt;@rockabs&lt;/a&gt;&amp;nbsp;Did you check in your id_token that all compulsory attributes (sub, name &amp;amp; email) are included ?&lt;/P&gt;
&lt;P&gt;When checking back your virtual proxy settings screenshot, I also noticed that you haven't set the "sub" attribute, which is a compulsory attribute.&lt;/P&gt;
&lt;P&gt;An attribute should exist in the id_token called the same value that the one you have set in the virtual proxy.&lt;/P&gt;
&lt;P&gt;Please also note that if the value of the "sub" attribute does not contain a domain name, then you also need to set a value in the "realm" field.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 09:18:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1862962#M4897</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-24T09:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1863110#M4900</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/29425"&gt;@Damien_V&lt;/a&gt;&amp;nbsp; As I see, It is not mentioned anywhere that it is mandatory?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.qlik.com/en-US/sense-admin/August2021/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/OIDC-configuration-Auth0.htm" target="_blank"&gt;https://help.qlik.com/en-US/sense-admin/August2021/Subsystems/DeployAdministerQSE/Content/Sense_DeployAdminister/QSEoW/Administer_QSEoW/Managing_QSEoW/OIDC-configuration-Auth0.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 13:38:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1863110#M4900</guid>
      <dc:creator>rockabs</dc:creator>
      <dc:date>2021-11-24T13:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense: How to request an OIDC token manually and check if correct attributes are included (PowerShell)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1863140#M4901</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/91754"&gt;@rockabs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll let our documentation team know so that they can add it on the Qlik help site.&lt;/P&gt;
&lt;P&gt;Thank you for noticing.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 14:08:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-How-to-request-an-OIDC-token-manually-and-check-if/tac-p/1863140#M4901</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2021-11-24T14:08:40Z</dc:date>
    </item>
  </channel>
</rss>

