OpenID Connect
OIDC
- Pronunciation
- OH-pun-eye-dee kuh-NEKT
In short
OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
What is OpenID Connect?
OAuth 2.0 was designed for authorization: letting an app access an API on a user's behalf. Many sites began using it for login, each in its own slightly different and often insecure way. OpenID Connect, finalized by the OpenID Foundation in 2014, standardized that: alongside the access token, the identity provider issues an ID token, a signed JWT with claims such as the user's unique ID, name and email.
The usual flow is the authorization code flow with PKCE. The app redirects the user to the provider, the user signs in there, and the provider redirects back with a one-time code. The app's server exchanges the code for tokens, verifies the ID token's signature, issuer, audience and expiry, and then creates its own session for the user.
Providers publish their settings at a discovery address, /.well-known/openid-configuration, including their endpoints and the public keys used to sign tokens, so libraries can configure themselves. "Sign in with Google", "Sign in with Apple", Microsoft Entra ID, Okta, Auth0 and Keycloak all speak OpenID Connect.
A common misconception is that OAuth and OpenID Connect are the same thing. OAuth answers what an app may access; OpenID Connect answers who the user is. Using a plain OAuth access token as proof of identity is a classic mistake, because the token wasn't necessarily issued for your application.
Key takeaways
- OpenID Connect adds authentication on top of OAuth 2.0.
- The provider issues a signed ID token (a JWT) describing the user.
- Apps use the authorization code flow with PKCE.
- Discovery documents publish endpoints and signing keys.
- OAuth is for access; OIDC is for identity.
Example
import { createRemoteJWKSet, jwtVerify } from "jose";
const issuer = "https://accounts.google.com";
const keys = createRemoteJWKSet(new URL("https://www.googleapis.com/oauth2/v3/certs"));
export async function verifyIdToken(idToken) {
const { payload } = await jwtVerify(idToken, keys, {
issuer,
audience: process.env.GOOGLE_CLIENT_ID, // the token must be meant for this app
});
// payload.sub is the user's stable ID; payload.email and payload.name describe them
return { userId: payload.sub, email: payload.email };
}Readers ask
What is the difference between OAuth and OpenID Connect?
OAuth 2.0 is an authorization framework that gives apps access tokens for APIs. OpenID Connect builds on it to provide authentication, adding the ID token and standard user information so apps can sign users in.
What is an ID token?
A JWT issued by the identity provider that states who the user is, for which application and until when. The app must verify its signature and claims before trusting it.
What is the difference between OpenID Connect and SAML?
Both provide single sign-on. SAML is older, XML-based and common in enterprise web apps. OpenID Connect is JSON- and JWT-based, simpler for mobile apps and APIs, and the usual choice for new applications.
Often compared
See also
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- SSOSecurity, p. 41SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- SAMLSecurity, p. 36SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- PasskeySecurity, p. 25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
Spotted a mistake or something missing on this page?Suggest an edit