Table des matières

🇫🇷 Français | 🇬🇧 English


Best Practices

Objective

Present the main security recommendations for integrating L’Identité Numérique La Poste.

👉 This page complements the OpenID Connect technical documentation.


General Principles

The partner remains responsible for:

LINLP secures authentication, but the integration must also be secured on the partner side.


Use a Secure Backend

⚠️ Mandatory

Sensitive calls must be performed server-side:

👉 The `client_secret` must never be exposed on the frontend.


Use HTTPS

⚠️ All exchanges must be protected through HTTPS:


Validate Tokens

The partner must validate `id_token` values:

👉 See: Token Validation


Retain the id_token

⚠️ Strong recommendation

The `id_token` constitutes:

👉 It should be retained according to the partner’s internal policies.


Secure Sessions

The partner must protect application sessions:


Internal Access Management

Restrict access to:


Logging

Keep appropriate records:

⚠️ Comply with GDPR rules and internal retention policies.


Data Protection

Apply the minimization principle:


Common Mistakes to Avoid

Bad Practice Risk
Unverified JWT Impersonation
Secret exposed in frontend Compromise
Long session without controls Session theft
Too many requested scopes Excessive data collection

Key Takeaways


Next Step

👉 Validate JWTs:

Token Validation