Dear Partners,
We are writing to provide an update on the production deployment of the `iss` parameter on the Corppass Authorization endpoint.
Following our previous communication, the production rollout has been rescheduled to 31 August 2026 to provide partners with additional time to complete the necessary implementation changes and testing.
The `iss` parameter change will be deployed to Production on 31 August 2026. All partners are required to ensure their integrations are ready before the rollout.
Action Required
If you have not already done so, please review and update your implementation to ensure it is compatible with the additional `iss` query parameter in the authorization callback response.
In particular, please ensure that:
- Your callback endpoint accepts the additional `iss` query parameter.
- Your application passes the complete authorization response (or at least all callback parameters, including `code`, `state`, and `iss`) to your OpenID Connect client library without filtering or reconstructing the callback parameters.
- Any callback parameter validation, URL rewriting, reverse proxies, API gateways, or WAF rules do not remove or reject the `iss` parameter.
If your application uses an OpenID Connect client library that consumes the OP discovery metadata, ensure the complete authorization response (including `iss`) is passed to the library. Otherwise, the authorization response may be rejected before the token exchange if `iss` is missing or does not match the configured issuer.
We strongly encourage you to validate your integration in the Staging environment, where this change is already available, and complete any required updates before 31 August 2026 to avoid disruption when the change is deployed to Production.
If you require additional assistance, please contact our support team here so that we can provide the necessary support.
Thank you for your continued support and partnership.
Best regards,
Corppass Team
Comments
0 comments
Please sign in to leave a comment.