As far as I know, dataverse generates nonce to avoid replay attacks when initiating OpenID flow. However, I am still not sure if dataverse really checks the nonce coming back from OpenID provider. Any idea?
Sorry, I have no idea. Oliver or Johannes might.
Last updated: Jan 09 2026 at 14:18 UTC