You are here. See how this question connects to other ideas.
Select a node to open its page · Expand to read within the map
One question
Does OpenID Connect solve the same problem as DID?
Separate a login protocol, an identifier and API authorization.
OpenID Connect (OIDC) adds an identity layer to OAuth 2.0. An application acting as a Relying Party (RP) interacts with an OpenID Provider (OP), receives an ID Token about authentication and validates it according to the protocol.
Imagine a workshop site using an identity provider for login. The site checks the accepted issuer, intended audience and validity period. A subject identifier must be understood with its issuer; a bare sub value is not a global identity across providers.
DID supplies naming and control foundations at a different layer. OIDC specifies an authentication interaction. Discussing identity does not make them interchangeable features. An ID Token is also not a blanket permit for business APIs; Access Tokens and resource authorization have separate roles.
Sources and further reading
Check your understanding
Does a valid ID Token authorize every API call?
No. An ID Token conveys authentication information; resource access follows its authorization rules.
Continue along a learning path
- Compare the layers of identity mechanismsStep 3 of 5