Skip to main content

Side by side

OAuthvsOpenID Connect

What is the difference between OAuth and OpenID Connect?

Updated 2 min read6 differences

In short

OAuth 2.0 lets an app access an API for a user with an access token; OpenID Connect adds an identity layer that says who the user is with a signed ID token.

OAuth

OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.

Read the page on OAuth

OpenID Connect

OIDC

OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.

Read the page on OpenID Connect

OAuth and OpenID Connect compared

AspectOAuthOpenID Connect
AnswersWhat may this app access?Who is the user?
PurposeAuthorizationAuthentication
Main tokenAccess token for APIsID token, a signed JWT
Built onStandalone frameworkOAuth 2.0
User informationNot standardizedStandard claims and a UserInfo endpoint
Typical useLetting apps call APIs on a user's behalfSign in with Google, single sign-on

The difference, explained

OAuth answers the question "what may this app do?". When you let a photo printing service read your Google Photos, OAuth lets Google issue it an access token with a limited scope, without giving it your password. The token is meant for the API, and the app doesn't necessarily learn who you are.

OpenID Connect, finalized in 2014, answers "who is this user?". It uses the same flows as OAuth 2.0, usually the authorization code flow with PKCE, but the identity provider also returns an ID token: a signed JWT with claims such as the user's unique ID, email and name, issued for one specific application. That is what powers "Sign in with Google" and enterprise single sign-on with providers such as Entra ID and Okta.

In practice they are used together. An app signs the user in with OpenID Connect, creates its own session, and, if it also needs to call APIs on the user's behalf, uses the OAuth access token from the same exchange. Libraries for OpenID Connect handle discovery, key rotation and token validation.

A common misconception is that OAuth alone is a login protocol. Using a plain access token as proof of identity is a known security mistake, because the token may have been issued to a different application. If you need to know who the user is, use OpenID Connect and validate the ID token.

Which one should you use?

Choose OAuth when…

  • An app needs delegated access to a user's data in another service.
  • You protect APIs with scoped access tokens.
  • Machine-to-machine access with client credentials.

Choose OpenID Connect when…

  • You need to sign users in with an external identity provider.
  • You want single sign-on across applications.
  • You need verified information about who the user is.

Readers ask

Is OpenID Connect the same as OAuth?

No. OpenID Connect is built on top of OAuth 2.0 and adds authentication, the ID token and standard user information. Every OIDC flow is an OAuth flow, but not the other way round.

Can I use OAuth for login?

Use OpenID Connect instead. Plain OAuth access tokens aren't designed to prove identity to your app, and treating them that way has led to real security holes.

What is the difference between an ID token and an access token?

An ID token tells your application who the user is and is meant to be read by it. An access token is sent to an API to authorize requests and is meant for that API.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings