SocialIdentity
What a provider hands back. Everything here is untrusted client input until a server verifies it — a debugger can hand your app any idToken it likes.
The server must, at minimum: verify the JWT signature against the provider's JWKS, check iss and aud, check exp, and check that the nonce claim equals SHA-256(rawNonce) — which is why rawNonce travels back with the identity instead of being discarded. Skipping the nonce check leaves the replay window that the nonce exists to close.
Properties
Apple only: one-time code your server exchanges for an access/refresh token pair.
Apple's user field, verbatim JSON, present only on the very first authorization. Apple never sends the name again — not on re-sign-in, not on token refresh. Persist it server-side on first sight or it is gone for that Apple ID forever (short of the user revoking the grant in Settings and starting over).