OpenID Connect (OIDC) ↗, also known as OIDC, is an open authentication protocol that allows you to authenticate to external source resources without the use of static credentials.
When using OIDC, you do not need to configure credentials for a source system in Foundry. Because of this, you can avoid duplicating source system credentials as long-lived secrets in Foundry. Instead, you will configure a trust relationship between Foundry and the source system. Foundry acts as the OIDC identity provider; every time a workflow in Foundry is required to authenticate with the source system (for example, a Data Connection sync), Foundry will issue an OIDC token with claims that identify the Data Connection source being used. The source system is able to validate those claims and provide a short-lived access token that can be used for subsequent interactions with the source system. The scope of that access token, such as the resources it is allowed to access, is managed entirely in the source system using the native authentication and authorization tools available. When configuring the trust relationship, you can add conditions to filter the incoming requests. Untrusted Foundry sources cannot request access tokens to resources in the source system they should not have access to.
The following sources support OIDC authentication. Refer to individual source documentation for more details on how to set up the trust relationship between OIDC and Palantir.
The following is an example OIDC token generated by Foundry:
{
"iss": "https://pltroidcpublicexample.blob.store.com/foundry",
"sub": "ri.magritte..source.7f3b8e21-4d9a-6c2e-1b7d-8a5f3c9e0b4f",
"aud": "your-source-system-audience",
"iat": <issued-at>,
"nbf": <not-before>,
"exp": <expiry>,
"jti": "<token-unique-identifier>",
"scp": "<additional-scope>",
}
| Claim | Claim type | Description |
|---|---|---|
| iss | issuer url | The URL that identifies Foundry as an OIDC identity provider. |
| sub | subject | The source RID of the Foundry source that is connecting to your source system. |
| aud | audience | The configured audience that identifies your source system. |
The source-rid should be used to filter incoming requests so untrusted Foundry sources cannot access your resources.
OIDC tokens generated by Foundry expire after one hour.
OIDC tokens are available to Data Connection syncs and also to Python environments such as external transforms, external functions, and compute modules. Use get_session_credentials() on the source to retrieve and renew tokens, as described in the Sources in Python documentation.
How you use the token depends on the source system. Some systems accept the Foundry-issued token directly as an OAuth token, while others require you to exchange it for a credential issued by the source system before making requests. Review the documentation for your source type for a complete example:
Because tokens expire after one hour, long-running jobs should request a new token from the source rather than reusing a token obtained at the start of the job.