/userinfo endpoint only show "sub" : "xxx"

What scopes are you passing in the authorize request? You also might want to check out this post regarding requesting an id token instead/as well:

2 Likes