OpenID Connect Concepts
OAuth vs OpenID Connect
Aspect
OAuth 2.0
OpenID Connect
The Identity Layer
┌────────────────────────────────────────┐
│ OpenID Connect │
│ (Authentication) │
├────────────────────────────────────────┤
│ OAuth 2.0 │
│ (Authorization) │
└────────────────────────────────────────┘The ID Token
Key Claims
Claim
Description
Standard Scopes
Scope
Claims
Authentication Flow
ID Token vs Access Token
Aspect
ID Token
Access Token
When to Use Which
UserInfo Endpoint
ID Token vs UserInfo
Aspect
ID Token
UserInfo
Discovery
Nonce
Authentication Patterns
Simple Login
Single Sign-On (SSO)
Silent Authentication
Security Considerations
Validate ID Tokens
Don't Trust Claims Blindly
Use ID Token for Authentication Only
Next Steps
Last updated
Was this helpful?