Auth and identity · Protocol

OpenID Connect

An identity layer on top of OAuth 2.0 that tells an app who the user is, in a standard signed token. It is how 'Sign in with Google' and 'Sign in with Microsoft' work.

Tokens and sessions · updated

How it works

OAuth on its own hands out access tokens that say what an app may do, not who the user is. OpenID Connect, finalised by the OpenID Foundation in 2014, adds the missing piece: when the app asks for the 'openid' scope, the provider also returns an ID token, a JWT with claims such as sub (a stable user id), email, name, iss (who issued it) and aud (which app it is for). The app verifies the signature and those claims, then starts its own session.

It also standardises the plumbing. A discovery document at /.well-known/openid-configuration lists a provider's endpoints and signing keys, so a library can connect to Google, Microsoft Entra ID, Okta, Auth0 or Keycloak with little more than a URL, a client id and a secret. That makes it the modern alternative to SAML for single sign-on, and it suits mobile apps, which SAML was never designed for.

More in Auth and identity

Tokens and sessions

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.