A login hint token is very different from the other tokens because it is created by the client (application) and not by the Authway. This token can be used to identify a user in different Single-sign-on scenarios or during Client Initiated Backchannel Authentication. The purpose of this token is to uniquely identify a user by the client to allow the Authway to sign-in the user in a better way.
Create a Login Hint Token
The login hint token must fullfil these requirements:
A valid JWT token.
Use the HS256 algorithm to sign the token.
Hash the shared client secret with SHA256 and use a base64 encoded hashed value as key when signing the token.
The issuer must be the client id that creates the SSO token.
Include an audience claim with the Identity Provider as audience.
Include an issued at (iat) claim with the time when the client created the SSO token.
Include a sub claim with the unique identifier of the user that should be signed in. If the identity is not knwon to the client (typically in CIBA) other identifiers such as e-mail, phone number or a social security number can be included.
Optionally include a tid claim. This is useful if the unique identifier is not known and passing it in the login hint token is an option to pass it in acr_values.