How it works
OAuth on its own hands out access tokens that say what an app may do, not who the user is. OpenID Connect, finalised by the OpenID Foundation in 2014, adds the missing piece: when the app asks for the 'openid' scope, the provider also returns an ID token, a JWT with claims such as sub (a stable user id), email, name, iss (who issued it) and aud (which app it is for). The app verifies the signature and those claims, then starts its own session.
It also standardises the plumbing. A discovery document at /.well-known/openid-configuration lists a provider's endpoints and signing keys, so a library can connect to Google, Microsoft Entra ID, Okta, Auth0 or Keycloak with little more than a URL, a client id and a secret. That makes it the modern alternative to SAML for single sign-on, and it suits mobile apps, which SAML was never designed for.
Related terms
More in Auth and identity
Tokens and sessions