Ephemeral Subject Identifier.
An ephemeral subject identifier is an OpenID Connect sub value that stays constant only for one authentication session and is never reused, so a relying party cannot link a user's separate visits.
Most relying parties treat the OIDC sub claim as the primary key for an account. The ephemeral subject type breaks that assumption on purpose. Per the specification, the value lasts for one authentication session and is never reused. The next time the same person signs in, the relying party sees a stranger.
That is the intended behavior, not a bug. The spec targets cases where the relying party should learn an attribute and nothing else. The spec itself frames this as unlinkability: one RP cannot link visits, and colluding RPs cannot correlate a user.
Practical consequence (our reading, not spec text). If you register for ephemeral identifiers, design the integration as an attribute check, not a login. Read the claims you need, make a decision, and do not create a persistent profile keyed on sub. Age-over-threshold checks and membership checks fit. Account recovery, saved preferences, and order history do not. Note too that the spec leaves refresh tokens, UserInfo, and logout behavior unaddressed, so test those paths with your OP.
The OIDC subject identifiers guide compares all three subject types and when to pick each. For the stable-but-unlinkable alternative, see pairwise subject identifiers.
Common questions
What is an ephemeral subject identifier in OpenID Connect?
It is a subject_type value, ephemeral, defined by OpenID Connect Ephemeral Subject Identifier 1.0. The sub claim stays the same for one authentication session and changes on the next visit. The OpenID Provider must never reuse a value, so the relying party cannot link visits through sub.
How is ephemeral different from public and pairwise?
A public sub is the same for every relying party. A pairwise sub differs per relying party (per sector identifier) but stays stable over time. An ephemeral sub differs per authentication session, so even the same relying party sees a new value each visit.
Is the Ephemeral Subject Identifier spec final?
The public review ran from July 17 to September 15, 2026, and the OpenID Foundation member vote on making it a Final Specification ran from September 16 to September 30, 2026. The vote closed on September 30, 2026; check the OpenID Foundation for the announced result.
Can I build user accounts on an ephemeral sub?
Not on the sub alone. Because the value changes every authentication session, there is nothing stable to key an account on. In practice ephemeral identifiers suit stateless checks, such as confirming a user is over a certain age or holds a membership, rather than returning-user accounts.
Related terms
In the guides
Identity Data Modeling: The Decision You Cannot Cheaply Undo
How to model users, organizations, memberships, and roles in B2B SaaS before the schema locks in, and why a tenant_id column on the user table is the most expensive shortcut in the category.
OpenID Connect (OIDC) Explained: The Modern Identity Layer on OAuth 2.0
OIDC adds authentication and identity claims to OAuth 2.0. How discovery, ID tokens, and the standard scopes work, plus the pitfalls that bite implementers in production.
Public, Pairwise, and Ephemeral Subject Identifiers in OpenID Connect
How OIDC's three subject identifier types differ, how an RP requests each, and why an ephemeral sub means you cannot key an account on it.