{"id":3778,"date":"2023-08-31T15:57:03","date_gmt":"2023-08-31T13:57:03","guid":{"rendered":"https:\/\/rock-the-prototype.com\/%category%\/openid-connect-oidc\/"},"modified":"2023-09-26T11:50:05","modified_gmt":"2023-09-26T09:50:05","slug":"openid-connect-oidc","status":"publish","type":"encyclopedia","link":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/","title":{"rendered":"OpenID Connect &#8211; OIDC"},"content":{"rendered":"<p><strong><a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid\/\" target=\"_blank\" title=\"All about OpenID - Discover everything you need to know about OpenID: from secure authentication and identity federation to the latest developments like OpenID Connect and the OpenID Foundation. Here you will find a comprehensive overview of digital identity.\" class=\"encyclopedia\">OpenID<\/a> Connect<\/strong> (<strong>OIDC<\/strong>) is an extension of the <strong>OAuth 2.0 protocol<\/strong> and is used for secure and efficient <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/authentication\/\" target=\"_blank\" title=\"Authentication is a multi-step process in identity management. Authentication in an IT system implements IT security functions that are realized by various security services and components.\" class=\"encyclopedia\">authentication<\/a> of users and technical services. <strong>OIDC<\/strong> stands for <strong>OpenID Connect<\/strong> and is an extension of the <a href=\"https:\/\/rock-the-prototype.com\/it-sicherheit\/openid\/\" target=\"_blank\" rel=\"noopener\"><strong>OpenID protocol<\/strong><\/a>. It was developed to overcome the limitations of the original OpenID standard and provides advanced security mechanisms and user information transfer.<\/p>\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ffffff;color:#ffffff\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ffffff;color:#ffffff\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Authorization_and_authentication_of_digital_identities\" >Authorization and authentication of digital identities<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Authentication\" >Authentication<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Example_of_a_valid_token_in_the_OIDC_authentication_process\" >Example of a valid token in the OIDC authentication process<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Authorization\" >Authorization<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#OIDC_explained_compactly\" >OIDC explained compactly:<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Background_and_development\" >Background and development<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Technical_basics\" >Technical basics<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Authentication_flow\" >Authentication flow<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Tokens\" >Tokens<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#OpenID_Connect_vs_OpenID\" >OpenID Connect vs. OpenID<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Significance_and_relevance_of_OpenID_Connect_in_software_development\" >Significance and relevance of OpenID Connect in software development<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Simplified_authentication\" >Simplified authentication<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Standardization\" >Standardization<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Improved_security\" >Improved security<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Federated_identities\" >Federated identities<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Use_case_diversity\" >Use case diversity<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Flexibility_and_expandability\" >Flexibility and expandability<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Data_efficiency_and_speed\" >Data efficiency and speed<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#OpenID_Foundation_and_Support\" >OpenID Foundation and Support<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#Conclusion\" >Conclusion<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Authorization_and_authentication_of_digital_identities\"><\/span><strong>Authorization and authentication of digital identities<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>OpenID Connect<\/strong> builds on the <a href=\"https:\/\/rock-the-prototype.com\/it-sicherheit\/oauth\/\" target=\"_blank\" rel=\"noopener\"><strong>OAuth 2.0 protocol<\/strong><\/a> developed for <strong>authorization<\/strong> and extends it to enable <strong>authentication<\/strong> as well.<\/p>\n<p>The terms &ldquo;<em>authentication<\/em>&rdquo; and &ldquo;<em>authorization<\/em>&rdquo; are often confused with each other or used interchangeably, although they represent <strong>different concepts in information security<\/strong>. Here, therefore, is an <strong>easy-to-understand explanation<\/strong> of the two <strong>IT security concepts<\/strong>:<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Authentication\"><\/span>Authentication<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Authentication is the process of verifying the identity of a person, system, or entity. Simply put, authentication ensures that you are who you say you are. This is usually done by entering a username and password, but it can also be done through other mechanisms such as biometrics, smart cards, or two-factor authentication (2FA).<\/p>\n<p><strong>In the context<\/strong> of <strong>OpenID<\/strong> and <strong>OpenID Connect<\/strong>, <strong>authenticatio<\/strong>n is the step where the user confirms <strong>their identity to an Identity Provider (IdP).<\/strong><\/p>\n<p>A <strong>successful authentication process<\/strong> usually results in the <strong>issuance of a token<\/strong> representing this confirmed identity.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Example_of_a_valid_token_in_the_OIDC_authentication_process\"><\/span>Example of a valid token in the OIDC authentication process<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Here you can see a <a href=\"https:\/\/rock-the-prototype.com\/en\/learn-programming\/json\/\" target=\"_blank\" title=\"What is JSON? JSON, the JavaScript Object Notation, is a lightweight and flexible data format that is ideal for cross-platform data exchange. It is easy to read, easy to write and is supported by almost all modern programming languages. Thanks to its lean structure, JSON enables efficient data transfer and is indispensable for web applications and APIs.\" class=\"encyclopedia\">JSON<\/a> web token as an illustrative example of a token with a cipher suite considered secure such as <code>ES256<\/code> (Elliptic Curve Digital Signature Algorithm) for the algorithm:<\/p>\n<p><strong>JWT Header:<\/strong><\/p>\n<p>{<br>\n&ldquo;alg&rdquo;: &ldquo;ES256&rdquo;,<br>\n&ldquo;kid&rdquo;: &ldquo;e9bc097a-ce51-4036-9562-d2ade882db0d&rdquo;<br>\n}<\/p>\n<p><strong>JWT Payload:<\/strong><\/p>\n<p>{<br>\n&ldquo;iss&rdquo;: &ldquo;https:\/\/identity-provider.com&rdquo;,<br>\n&ldquo;sub&rdquo;: &ldquo;1234567890abcdef&rdquo;,<br>\n&ldquo;aud&rdquo;: &ldquo;your-client-id&rdquo;,<br>\n&ldquo;exp&rdquo;: 1621843200,<br>\n&ldquo;iat&rdquo;: 1621842600,<br>\n&ldquo;nonce&rdquo;: &ldquo;random-nonce-string&rdquo;,<br>\n&ldquo;auth_time&rdquo;: 1621842600<br>\n}<\/p>\n<p>This example uses the <strong>ES256 algorithm<\/strong>, which uses <strong>elliptic curve cryptography (ECC)<\/strong> and is still considered secure. The <code>kid<\/code> (Key ID) would be an identifier for the public key used to verify the token.<\/p>\n<p>After the header and payload are generated, they would be encoded and signed with the identity provider&rsquo;s private key to produce the full JWT. It would be a combination of these encoded and signed values, separated by dots <code>.<\/code>.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Authorization\"><\/span>Authorization<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>After authentication comes authorization. It determines which resources or actions the authenticated user or system may access or perform. These can be files, databases, APIs and other protected resources. Authorization therefore ensures that you are only allowed to do what you are authorized to do.<\/p>\n<p>In the context of OpenID and OAuth 2.0, authorization is often the next step after authentication. Here, an <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/access-token\/\" target=\"_blank\" title=\"What is an access token? Access tokens are digital keys that allow a client access to protected server resources as soon as a user is successfully authenticated. You should definitely be familiar with these tokens as an integral part of the OAuth 2.0 specification, as they are used for secure authorization. Learn more about software development and IT security now...\" class=\"encyclopedia\">access token<\/a> is issued to the client (the application that authenticated the user). This token defines which resources the client is allowed to retrieve or manipulate on behalf of the user.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"OIDC_explained_compactly\"><\/span>OIDC explained compactly:<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Authentication<\/strong>: Confirms that you are who you say you are.<\/li>\n<li><strong>Authorization<\/strong>: Determines what you are allowed to do after your identity has been confirmed.<\/li>\n<\/ul>\n<p>Both concepts are critical in the context of information security and when dealing with identity management in digital systems, and they often work hand in hand to provide a comprehensive security mechanism.<\/p>\n<p>OIDC is thus much more flexible and secure than the original OpenID protocol. It also allows the transfer of more user information and has advanced security features. OIDC is now the common <strong>Auth standard protocol<\/strong> and has replaced OpenID in many applications.<\/p>\n<ul>\n<li><strong>Authentication:<\/strong> Verification of the identity of a user or a service.<\/li>\n<li><strong>OAuth 2.0<\/strong>: An open standard protocol for secure API authorization.<\/li>\n<li><strong>Identit&auml;tsprovider (IdP)<\/strong>: A service that manages user identities and provides authentication services.<\/li>\n<li><strong>Token<\/strong>: A short piece of data that serves as an identifier or access key.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Background_and_development\"><\/span>Background and development<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The OpenID Foundation launched OIDC as a modernized version of the original OpenID standard to better meet the needs of today&rsquo;s complex digital ecosystems. It offers enhanced capabilities for transferring user information and improved security features.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Technical_basics\"><\/span>Technical basics<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Authentication_flow\"><\/span>Authentication flow<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>OpenID Connect uses several authentication flows based on the OAuth 2.0 <a href=\"https:\/\/rock-the-prototype.com\/en\/programming-languages-frameworks\/framework\/\" target=\"_blank\" title=\"A framework is a set of guidelines or rules that provides a structure for the organization and development of code in a particular programming language or platform. The framework serves as a basis or blueprint on which to build when developing software applications.\" class=\"encyclopedia\">framework<\/a>. The most commonly used rivers are:<\/p>\n<ol>\n<li><strong>Authorization Code Flow<\/strong>: Suitable for server-to-server authentication.<\/li>\n<li><strong>Implicit Flow<\/strong>: Suitable for browser-based applications.<\/li>\n<li><strong>Hybrid Flow<\/strong>: A combination of the two rivers mentioned above.<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"Tokens\"><\/span>Tokens<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>OpenID Connect uses several types of tokens:<\/p>\n<ul>\n<li><strong>ID Token<\/strong>: Contains the user&rsquo;s identity information.<\/li>\n<li><strong>Access Token<\/strong>: Used to access protected resources.<\/li>\n<li><strong><a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/refresh-token\/\" target=\"_blank\" title=\"What is a refresh token? Refresh tokens are essential components of modern authentication systems and an indispensable element in protocols such as OAuth 2.0 to enable the secure management of access rights to web resources. Find out more about how Refresh Token works and its life cycle...\" class=\"encyclopedia\">Refresh Token<\/a><\/strong>: Used to obtain new Access Tokens without having to authenticate the user again.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"OpenID_Connect_vs_OpenID\"><\/span>OpenID Connect vs. OpenID<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>While OpenID was primarily designed for authentication, OpenID Connect extends these capabilities with the ability to securely and efficiently transfer additional user information.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Significance_and_relevance_of_OpenID_Connect_in_software_development\"><\/span>Significance and relevance of OpenID Connect in software development<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>OpenID Connect (OIDC) has important meaning and relevance in software development because it provides a standardized method for authenticating users. It builds on the OAuth 2.0 protocol and extends it with the ability to exchange both identity information and authentication information between the identity provider and the service provider. Here are some reasons why OpenID Connect is so relevant in software development:<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Simplified_authentication\"><\/span>Simplified authentication<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The use of OIDC facilitates the implementation of secure authentication methods. Developers don&rsquo;t have to build their own authentication systems from scratch, which saves time and reduces potential points of failure.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Standardization\"><\/span>Standardization<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>OIDC provides an industry standard that is supported by many large companies and organizations. This standardization greatly facilitates the integration of various services and applications.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Improved_security\"><\/span>Improved security<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Compared to simple authentication methods such as username and password, OIDC offers advanced security features such as multi-factor authentication, short-lived tokens, and automatic token renewal.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Federated_identities\"><\/span>Federated identities<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Through OIDC, users can share their identity across different services without having to create new credentials each time. This is not only user-friendly, but also enables a secure and consistent user experience across different services.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Use_case_diversity\"><\/span>Use case diversity<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>OIDC can be used in a variety of use cases, from web and mobile applications to API security and <a href=\"https:\/\/rock-the-prototype.com\/en\/software-architecture\/microservices\/\" target=\"_blank\" title=\"Microservices are small, autonomous services that work together. The key to a good microservice architecture lies in the implementation of small and autonomous microservices.\" class=\"encyclopedia\">microservices<\/a> architectures.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Flexibility_and_expandability\"><\/span>Flexibility and expandability<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>By using JSON Web Tokens (JWT) for identity information, OIDC provides a flexible and extensible structure that can be easily customized to meet specific requirements.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Data_efficiency_and_speed\"><\/span>Data efficiency and speed<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>OIDC is designed to exchange minimal amounts of data between the client and the server, resulting in faster processing and lower network latencies.<\/p>\n<p>Overall, OpenID Connect&rsquo;s standardization, security features and flexibility make it an attractive option for authentication and identity management in modern software development projects.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"OpenID_Foundation_and_Support\"><\/span>OpenID Foundation and Support<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <a href=\"https:\/\/openid.net\/foundation\/\" target=\"_blank\" rel=\"noopener\">OpenID Foundation<\/a> offers a wealth of information such as specification details, as well as training, partnerships and a certification program. With these offerings, the Foundation promotes the dissemination and implementation of OIDC and, in return, guarantees its interoperability and security.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>OpenID Connect is an advanced protocol for secure and efficient authentication in the modern digital world. By extending the OAuth 2.0 framework, it provides improved functionality and addresses the limitations of the original OpenID standard.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenID Connect (OIDC) is an extension of the OAuth 2.0 protocol and is used for secure and efficient authentication of users and technical services. OIDC stands for OpenID Connect and is an extension of the OpenID protocol.<\/p>\n","protected":false},"author":1,"featured_media":3720,"template":"","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0},"categories":[1232],"tags":[1354,1255,1256,1356,1357,1358,1355,1359,1361,1353,1360],"class_list":["post-3778","encyclopedia","type-encyclopedia","status-publish","has-post-thumbnail","hentry","category-it-security","tag-access-token-en","tag-authentication","tag-authorization","tag-identity-provider-en","tag-identity-provider-en-2","tag-it-security-concepts","tag-oauth-en","tag-token-en","tag-token-exchange-en","tag-token-flow-en","tag-tokenflow-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>OpenID Connect - OIDC - IT Security &amp; Secure Digital Identities<\/title>\n<meta name=\"description\" content=\"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OpenID Connect - OIDC - IT Security &amp; Secure Digital Identities\" \/>\n<meta property=\"og:description\" content=\"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/\" \/>\n<meta property=\"og:site_name\" content=\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-26T09:50:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2023\/08\/OpenID-Connect.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1300\" \/>\n\t<meta property=\"og:image:height\" content=\"1300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/\",\"name\":\"OpenID Connect - OIDC - IT Security & Secure Digital Identities\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/OpenID-Connect.png\",\"datePublished\":\"2023-08-31T13:57:03+00:00\",\"dateModified\":\"2023-09-26T09:50:05+00:00\",\"description\":\"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/OpenID-Connect.png\",\"contentUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/OpenID-Connect.png\",\"width\":1300,\"height\":1300,\"caption\":\"OpenID-Connect - Autorisierung und Authentifizierung von digitalen Identit\u00e4ten\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/openid-connect-oidc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/rock-the-prototype\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Prototyping Wiki\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/wiki\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"OpenID Connect &#8211; OIDC\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/\",\"name\":\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\",\"description\":\"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OpenID Connect - OIDC - IT Security & Secure Digital Identities","description":"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/","og_locale":"en_US","og_type":"article","og_title":"OpenID Connect - OIDC - IT Security & Secure Digital Identities","og_description":"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!","og_url":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/","og_site_name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","article_modified_time":"2023-09-26T09:50:05+00:00","og_image":[{"width":1300,"height":1300,"url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2023\/08\/OpenID-Connect.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/","url":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/","name":"OpenID Connect - OIDC - IT Security & Secure Digital Identities","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#primaryimage"},"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2023\/08\/OpenID-Connect.png","datePublished":"2023-08-31T13:57:03+00:00","dateModified":"2023-09-26T09:50:05+00:00","description":"OpenID Connect enables authorization and authentication of digital identities \u2705 Ident Provider with OIDC \u2705 Learn more now!","breadcrumb":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#primaryimage","url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2023\/08\/OpenID-Connect.png","contentUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2023\/08\/OpenID-Connect.png","width":1300,"height":1300,"caption":"OpenID-Connect - Autorisierung und Authentifizierung von digitalen Identit\u00e4ten"},{"@type":"BreadcrumbList","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/openid-connect-oidc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/rock-the-prototype.com\/en\/rock-the-prototype\/"},{"@type":"ListItem","position":2,"name":"Prototyping Wiki","item":"https:\/\/rock-the-prototype.com\/en\/wiki\/"},{"@type":"ListItem","position":3,"name":"OpenID Connect &#8211; OIDC"}]},{"@type":"WebSite","@id":"https:\/\/rock-the-prototype.com\/en\/#website","url":"https:\/\/rock-the-prototype.com\/en\/","name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","description":"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rock-the-prototype.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/encyclopedia\/3778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/users\/1"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media\/3720"}],"wp:attachment":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media?parent=3778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/categories?post=3778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/tags?post=3778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}