The sso.openid.profile..user.claim setting for OpenID Connect configuration uses a JSON attribute path. This is the path to the claim that contains username values within a JSON payload. This is a period delimited grammar, that can be used to traverse into nested JSON objects.