Skip to main content
Book 07 · SecurityPage 23 of 50

OpenID Connect

OIDC

Pronunciation
OH-pun-eye-dee kuh-NEKT
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/openid-connect

In short

OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.

What is OpenID Connect?

OAuth 2.0 was designed for authorization: letting an app access an API on a user's behalf. Many sites began using it for login, each in its own slightly different and often insecure way. OpenID Connect, finalized by the OpenID Foundation in 2014, standardized that: alongside the access token, the identity provider issues an ID token, a signed JWT with claims such as the user's unique ID, name and email.

The usual flow is the authorization code flow with PKCE. The app redirects the user to the provider, the user signs in there, and the provider redirects back with a one-time code. The app's server exchanges the code for tokens, verifies the ID token's signature, issuer, audience and expiry, and then creates its own session for the user.

Providers publish their settings at a discovery address, /.well-known/openid-configuration, including their endpoints and the public keys used to sign tokens, so libraries can configure themselves. "Sign in with Google", "Sign in with Apple", Microsoft Entra ID, Okta, Auth0 and Keycloak all speak OpenID Connect.

A common misconception is that OAuth and OpenID Connect are the same thing. OAuth answers what an app may access; OpenID Connect answers who the user is. Using a plain OAuth access token as proof of identity is a classic mistake, because the token wasn't necessarily issued for your application.

Key takeaways

  • OpenID Connect adds authentication on top of OAuth 2.0.
  • The provider issues a signed ID token (a JWT) describing the user.
  • Apps use the authorization code flow with PKCE.
  • Discovery documents publish endpoints and signing keys.
  • OAuth is for access; OIDC is for identity.

Example

Checking an ID token on the server (Node.js with jose)javascript
import { createRemoteJWKSet, jwtVerify } from "jose";

const issuer = "https://accounts.google.com";
const keys = createRemoteJWKSet(new URL("https://www.googleapis.com/oauth2/v3/certs"));

export async function verifyIdToken(idToken) {
  const { payload } = await jwtVerify(idToken, keys, {
    issuer,
    audience: process.env.GOOGLE_CLIENT_ID,   // the token must be meant for this app
  });
  // payload.sub is the user's stable ID; payload.email and payload.name describe them
  return { userId: payload.sub, email: payload.email };
}

Readers ask

What is the difference between OAuth and OpenID Connect?

OAuth 2.0 is an authorization framework that gives apps access tokens for APIs. OpenID Connect builds on it to provide authentication, adding the ID token and standard user information so apps can sign users in.

What is an ID token?

A JWT issued by the identity provider that states who the user is, for which application and until when. The app must verify its signature and claims before trusting it.

What is the difference between OpenID Connect and SAML?

Both provide single sign-on. SAML is older, XML-based and common in enterprise web apps. OpenID Connect is JSON- and JWT-based, simpler for mobile apps and APIs, and the usual choice for new applications.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings