OpenID Connect (OIDC)
OpenID Connect (OIDC) is an authentication standard that builds on OAuth 2.0 and enables the identity verification of users. While OAuth 2.0 primarily governs authorization, OpenID Connect extends the framework with the secure transmission of identity information.
At its core is the ID token, a signed JSON Web Token (JWT) that contains verified statements (claims) about the user – such as identifier, name or email address. Via a standardized discovery mechanism, applications find the endpoints of the identity provider automatically, which considerably simplifies integrations. Applications thus receive structured, verifiable user information without having to implement their own authentication processes.
OpenID Connect is used above all for single sign-on in web and mobile applications and as the technical basis of social login. Compared with the older SAML, OIDC is more lightweight (JSON/REST instead of XML) and better suited to mobile apps and APIs; in grown enterprise landscapes, both standards frequently exist in parallel.