Pairwise Subject Identifier.
A pairwise subject identifier is an OpenID Connect sub value that is different for each relying party (per sector identifier) but stable over time, so one user cannot be correlated across unrelated apps by sub.
Pairwise identifiers are the default privacy choice for most consumer OIDC deployments that need accounts. The relying party still gets a stable key, so returning users, saved data, and account recovery work normally. What it loses is the ability to join its records with another, unrelated RP's records using sub.
The sector identifier is where teams slip. If your app uses several hostnames, such as a web app and a separate mobile callback domain, each host can receive a different sub for the same person. Register a sector_identifier_uri up front so all of your hosts share one pairwise value.
Compare the three types before you pick. Public identifiers are simplest but linkable across RPs. Pairwise is stable per sector. Ephemeral identifiers change every session and do not support accounts at all. The OIDC subject identifiers guide walks through the decision.
Common questions
What is a pairwise subject identifier?
It is an OpenID Connect subject_type where the provider issues a different sub to each relying party, grouped by sector identifier. The same user gets a stable value at one app and an unrelated value at another, which prevents correlation through sub.
What is sector_identifier_uri used for?
It lets one relying party with several redirect URI hosts receive the same pairwise sub across them. The RP registers an HTTPS URL that returns a JSON array of its redirect URIs, and the OP uses that URL's host as the sector identifier instead of each redirect host.
What is the difference between public, pairwise, and ephemeral sub?
Public is one sub for all relying parties. Pairwise is one sub per sector, stable over time. Ephemeral is one sub per authentication session, never reused. Each step trades linkability for less ability to recognize a returning user.
Can I migrate from public to pairwise identifiers?
Changing subject_type changes every user's sub, so existing accounts keyed on the old value will not match. Plan a migration that links old and new identifiers, for example by matching a verified email during a transition window, before switching.
Related terms
In the guides
Identity Data Modeling: The Decision You Cannot Cheaply Undo
How to model users, organizations, memberships, and roles in B2B SaaS before the schema locks in, and why a tenant_id column on the user table is the most expensive shortcut in the category.
OpenID Connect (OIDC) Explained: The Modern Identity Layer on OAuth 2.0
OIDC adds authentication and identity claims to OAuth 2.0. How discovery, ID tokens, and the standard scopes work, plus the pitfalls that bite implementers in production.
Public, Pairwise, and Ephemeral Subject Identifiers in OpenID Connect
How OIDC's three subject identifier types differ, how an RP requests each, and why an ephemeral sub means you cannot key an account on it.