P55 · OAuth 2.0 / OIDC & Federated Identity
authorization-code + PKCE, OIDC, JWT, SAML
Delegated authorization and token-based identity — the OAuth 2.0 authorization-code flow with PKCE, verifying JWTs safely, and OpenID Connect federation & single sign-on.
"Sign in with Google" looks like authentication and is not. OAuth 2.0 is a delegation protocol: it exists so that you can let an application act on your behalf at another service without ever handing it your password, and so that you can take the permission back later without changing that password. Conflating delegated access with proof of identity is the single most common OAuth mistake, and it is the one this pillar disposes of first — because the fix, OpenID Connect, is a layer built on top precisely to supply the identity OAuth deliberately does not.
From there the pillar follows the protocol as a sequence of defences. The
authorization-code flow keeps the token off the front channel; PKCE protects the
public client that cannot keep a secret at all; the state parameter and strict
redirect-URI matching close the two openings an attacker would otherwise use. You
then verify a JWT the only way that teaches anything — by implementing HS256
yourself, then breaking your own verifier twice. alg:none succeeds if you
believe the token's own header about how it should be checked, and key confusion
succeeds if an RS256 public key is fed to an HMAC verifier as a shared secret;
both are fixed by deciding the algorithm before you read the token, and by
checking exp, aud and iss every time rather than when it seems relevant.
The pillar closes on OIDC and federation: id_token against access_token,
claim validation, discovery and JWKS for key rotation, and how single sign-on
across organisations is assembled from these parts.