freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #38 of 45

openid connect · oauth + identity

RestaVSThe 401 Bandit
Resta saysOpenID Connect adds an identity layer on top of OAuth 2.0 — for login, not just access.

OAuth grants access; OpenID Connect (OIDC) adds identity. On top of OAuth, OIDC returns an ID token (a JWT with verified user info — sub, email, name). So "Sign in with Google" is really OIDC: you get both a token to call APIs and trustworthy identity claims about who logged in. Use OIDC when you need authentication, not just delegated access.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why OIDC, not bare OAuth, is the right tool for "log in with X".

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>OAuth   → access token (call APIs)
OIDC    → + ID token (verified who you are)
login   → needs OIDC</pre></body></html>
▶ Open the interactive comic issue
‹ Oauth · Client Credentials · Device CodeJwt · The Self-Contained Token ›