Home / Companies / Google Cloud / Blog / Post Details
Content Deep Dive

Enhance Security and Trust: New Session Metadata in Sign in with Google

Blog post from Google Cloud

Post Details
Company
Date Published
Author
Sergei Akulich, and Brian Daugherty
Word Count
786
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to the increasing threats of phishing and online abuse, Google has introduced new session metadata claims, auth_time and amr, within its Sign in with Google feature, aimed at enhancing security for verified apps using OpenID Connect (OIDC) standards. These claims, included in the ID Token, provide insights into when and how users authenticate, thereby enabling platforms to implement more dynamic, risk-based access controls. Auth_time offers a timestamp of the last successful authentication, helping platforms enforce session policies, while amr details the authentication methods used, such as passwords or multi-factor authentication, facilitating more granular access controls. These enhancements aim to reduce security incidents and fraudulent activities by providing platforms with better tools to manage and secure user sessions across Android, iOS, and web applications. By leveraging Google's authentication infrastructure, applications can benefit from reduced security burdens and improve their overall security posture without drastically altering existing authentication flows.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.