Resta saysOpenID Connect adds an identity layer on top of OAuth 2.0 — for login, not just access.
OAuth grants access; OpenID Connect (OIDC) adds identity. On top of OAuth, OIDC returns an ID token (a JWT with verified user info — sub, email, name). So "Sign in with Google" is really OIDC: you get both a token to call APIs and trustworthy identity claims about who logged in. Use OIDC when you need authentication, not just delegated access.
Power-ups you unlock
OIDC = OAuth + an identity layer
Returns an ID token (JWT) with user claims
The real basis of social login
OAuth alone is authorization, not login
The 401 Bandit attacks — common mistakes
Using raw OAuth for login (no identity guarantees)
Trusting the access token for identity
Not verifying the ID token’s signature
Boss battleExplain why OIDC, not bare OAuth, is the right tool for "log in with X".
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>OAuth → access token (call APIs)
OIDC → + ID token (verified who you are)
login → needs OIDC</pre></body></html>