Dear Partners,
This is a follow up regarding the addition of the `iss` (issuer) parameter to the Corppass Authorization endpoint callback response.
The change has now been successfully deployed to the Production environment as of 23 July 2026.
What has changed
As previously communicated, the Authorization endpoint callback response now includes the parameter: `iss=https://id.corppass.gov.sg`. This applies to both the Legacy API and the Financial-grade API (FAPI) 2.0. This change aligns with OAuth 2.0 security best practices by explicitly identifying the Authorization Server that issued the response.
What you need to do
If you have not yet updated your implementation, please do so as soon as possible. Applications that reject or filter unknown callback parameters (for example, through strict query string validation, URL allowlists, or WAF/proxy rules) may experience authentication issues.
If you have already reviewed your implementation and confirmed that your application accepts this additional parameter, no further action is required.
If you encounter any issues following this deployment or require assistance, please contact our support team here.
Thank you for your continued partnership.
Best regards,
Corppass Team
Comments
0 comments
Please sign in to leave a comment.