OIDC & federated identity
P55.oidc-federation.01 · Audience: guest, it-ml, language-pro · Prerequisites: JWTs: structure, verification, pitfalls
OAuth authorizes; OpenID Connect authenticates — it adds an id_token that says who the
user is. This module validates an id_token's claims (verifying the signature is not enough:
you must check who it was minted for), then steps back to OAuth-vs-OIDC, SSO and federation.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — validate an OIDC id_token's claims
Loading exercise…
Interview rung — OAuth vs OIDC & federation (free-form)
Loading exercise…
My notes on this module
Loading your notes...