Hi Matt,
Thanks for the reply. To clarify, is it just the sandbox that isn't compliant with the OpenID Connect specification regarding handling of nonce, or Cerner production deploys as well?
https://openid.net/specs/openid-connect-core-1_0.html#CodeIDToken"If a nonce value was sent in the Authentication Request, a nonce Claim MUST be present and its value checked to verify that it is the same value as the one that was sent in the Authentication Request."
Regards,
David