OAuth 2.0 vs OpenID Connect (OIDC)
The simplest difference is:
OAuth 2.0 = Authorization — What are you allowed to access?
OpenID Connect = Authentication — Who are you?
OpenID Connect is built on top of OAuth 2.0.
1. Basic Difference
OAuth 2.0
|
v
Authorization
|
v
"What can you access?"
OpenID Connect
|
v
Authentication
|
v
"Who are you?"
For example:
OAuth:
"Syed can read orders."
OIDC:
"This authenticated user is Syed."
2. What Is OAuth 2.0?
OAuth 2.0 is an authorization framework.
Its primary purpose is to allow a client application or service to obtain controlled access to a protected resource/API.
Example:
Angular
|
| Access Token
v
Order API
The token might grant:
orders.read
orders.create
The API uses those permissions to determine what operations are allowed.
3. What Is OpenID Connect?
OpenID Connect is an authentication protocol/identity layer built on OAuth 2.0.
Its purpose is to allow an application to establish the identity of the authenticated user.
Example:
User
|
| Login
v
Identity Provider
|
| ID Token
v
Angular Application
The application can establish identity information such as:
User ID
Name
Email
depending on the claims provided.
4. Most Important Difference — Tokens
This is one of the most important interview points.
OAuth 2.0
Primarily uses an:
Access Token
The access token is intended for the API/resource server.
Client
|
| Access Token
v
Web API
OpenID Connect
Introduces an:
ID Token
The ID token is intended for the client application.
Identity Provider
|
| ID Token
v
Client Application
OIDC flows can also obtain an access token when the application needs to call an API.
5. Access Token vs ID Token
| Access Token | ID Token |
|---|---|
| Associated with OAuth 2.0 | Introduced by OIDC |
| Used for API access | Used to communicate authentication information to client |
| Sent to API | Consumed by client |
| Represents delegated/application authorization | Represents authenticated user/session claims |
| Audience normally resource/API | Audience normally client application |
| Can contain scopes/roles/permissions | Contains identity/authentication claims |
Remember:
Access Token
|
v
API
ID Token
|
v
Client
6. Example
Suppose you have:
Angular
+
ASP.NET Core Web API
+
Microsoft Entra ID
The user logs in.
User
|
v
Angular
|
| Login
v
Identity Provider
|
| Authenticate
v
Authorization Code
|
v
Angular
|
| Code + PKCE
v
Identity Provider
The application can receive/use:
Identity Provider
|
+---------+---------+
| |
v v
ID Token Access Token
| |
v v
Angular Web API
The distinction is:
ID Token
↓
Who authenticated?
Access Token
↓
What API access is granted?
7. Example ID Token
Conceptually:
{
"sub": "1001",
"name": "Syed",
"email": "syed@example.com",
"iss": "https://identity.example.com",
"aud": "angular-client"
}
The client uses the ID token as part of establishing the authenticated user's identity/session.
8. Example Access Token
Conceptually:
{
"sub": "1001",
"aud": "order-api",
"scope": "orders.read orders.create",
"iss": "https://identity.example.com",
"exp": 1790690000
}
The API uses it to authorize requests.
For example:
GET /api/orders
Authorization: Bearer <access_token>
9. Important Rule
Don't use the ID token as the credential for calling your API.
Wrong:
Angular
|
| ID Token
v
Order API
Use:
Angular
|
| Access Token
v
Order API
The two tokens have different intended recipients and purposes.
10. openid Scope
OIDC uses the special:
openid
scope.
For example:
openid
profile
email
orders.read
Conceptually:
openid
|
+--> Request OpenID Connect authentication
profile
|
+--> Request standard profile information
email
|
+--> Request email claims
orders.read
|
+--> Request API authorization
The presence of openid makes the authorization request an OpenID Connect request.
11. OAuth in Microservices
OAuth is especially important for API authorization and service-to-service communication.
For example:
Order Service
|
| Client Credentials
v
Authorization Server
|
| Access Token
v
Order Service
|
| Access Token
v
Payment Service
Here:
No user login
No ID Token required
Order Service is acting as itself.
Therefore:
OAuth 2.0 Client Credentials
is appropriate.
12. OIDC in Microservices
OIDC becomes relevant when there is a user authentication requirement.
For example:
User
|
| Login
v
Angular
|
v
Identity Provider
OIDC authenticates the user.
Then the client uses an OAuth access token to call APIs:
User
|
v
Angular
|
| Access Token
v
API Gateway
|
v
Order Service
13. Complete Real-World Architecture
Consider:
Microsoft Entra ID
^
|
OAuth + OpenID Connect
|
|
User -----------> Angular Application
|
| Access Token
v
API Gateway
|
v
Order Service
|
| OAuth
| Client Credentials
|
| Service Access Token
v
Payment Service
There are two different scenarios here.
User authentication
User
↓
OIDC
↓
Identity Provider
↓
Authenticated User
API authorization
Angular
↓
OAuth Access Token
↓
Order API
Service-to-service authorization
Order Service
↓
OAuth Client Credentials
↓
Access Token
↓
Payment Service
14. OAuth Doesn't Mean "Login"
A common interview mistake is saying:
"OAuth is used to authenticate the user."
OAuth 2.0 itself is primarily about authorization.
OIDC adds standardized authentication on top of OAuth.
OAuth
↓
Authorization
OIDC
↓
Authentication
15. OAuth vs OIDC vs JWT
These three terms are frequently confused.
| Technology | What is it? | Purpose |
|---|---|---|
| OAuth 2.0 | Authorization framework | API/resource authorization |
| OpenID Connect | Identity/authentication protocol | User authentication |
| JWT | Token format | Represent signed claims |
So:
OAuth 2.0
!=
OIDC
!=
JWT
But they often work together.
16. How They Work Together
OAuth 2.0
|
Authorization
|
+---- Access Token
|
|
OpenID Connect
|
Authentication
|
+---- ID Token
The ID token is a JWT.
OAuth access tokens may also be JWTs, depending on the authorization server.
17. Simple Real-Life Example
Think about entering an office.
OpenID Connect
Security asks:
Who are you?
Name: Syed
Employee ID: 1001
That's authentication.
OAuth
After identifying you, the system determines:
What can you access?
Reception ✓
Development ✓
Finance ✗
Server Room ✗
That's authorization.
Therefore:
OIDC
=
Who are you?
OAuth
=
What can you access?
18. Advantages of OAuth 2.0
- Standardized API authorization
- Supports fine-grained permissions
- Access tokens can be short-lived
- Users don't give their passwords to resource APIs
- Supports service-to-service authentication/authorization
- Works well with distributed systems
- Supports multiple authorization flows
- Centralizes authorization infrastructure
19. Advantages of OIDC
- Standardized user authentication
- Supports Single Sign-On
- Supports federated identity
- Provides ID Tokens
- Standard identity claims
- Integrates naturally with OAuth
- Supported by major identity providers
Examples include:
Microsoft Entra ID
Google
Keycloak
Auth0
Duende IdentityServer
20. Disadvantages
Both OAuth/OIDC introduce additional concepts and infrastructure:
Identity Provider
Client Registration
Redirect URI
Scopes
Claims
Access Tokens
ID Tokens
Refresh Tokens
PKCE
Token Validation
Key Rotation
Misconfiguration can also create security problems.
For production applications, use established OAuth/OIDC libraries rather than implementing these protocols yourself.
21. Key Points
For interviews, remember these:
- OAuth 2.0 is primarily for authorization.
- OIDC is for authentication/identity.
- OIDC is built on OAuth 2.0.
- OAuth uses Access Tokens to access protected APIs.
- OIDC introduces the ID Token.
- ID Token → intended for the client.
- Access Token → intended for the API.
openidindicates an OIDC request.- Authorization Code + PKCE is commonly used for interactive clients.
- Client Credentials is commonly used for service-to-service access.
- OAuth is not the same as JWT.
- OIDC is not the same as JWT.
- JWT is a token format.
- OIDC ID Tokens are JWTs.
- OAuth access tokens may be JWTs, but don't have to be.
22. Interview Questions and Answers
Q1. OAuth 2.0 vs OpenID Connect?
Answer:
OAuth 2.0 is an authorization framework used to grant clients access to protected resources through access tokens.
OpenID Connect is an authentication protocol built on OAuth 2.0 that allows applications to authenticate users and obtain identity information, including through an ID Token.
Q2. Which is used for authentication?
OpenID Connect.
OIDC
↓
Authentication
Q3. Which is used for authorization?
OAuth 2.0.
OAuth
↓
Authorization
Q4. What token does OAuth use for API access?
An:
Access Token
Client
|
| Access Token
v
API
Q5. What token does OpenID Connect introduce?
An:
ID Token
Identity Provider
|
| ID Token
v
Client
Q6. Should an ID Token be sent to a Web API?
Normally, no.
Use an access token when calling the API:
Client
|
| Access Token
v
Web API
The ID token is intended for the client application.
Q7. Can OAuth be used without OpenID Connect?
Yes.
For example, service-to-service communication:
Order Service
|
| OAuth Client Credentials
v
Authorization Server
|
| Access Token
v
Payment Service
There is no user authentication requirement, so OIDC is unnecessary for that specific interaction.
Q8. Can OpenID Connect exist without OAuth?
OIDC is built on top of OAuth 2.0, so it uses OAuth's authorization infrastructure and extends it with identity/authentication capabilities.
Q9. Is an Access Token always JWT?
No.
An OAuth access token can be:
JWT
or an opaque/reference token, depending on the authorization server.
Q10. Is an ID Token a JWT?
Yes. The OIDC ID Token is represented as a JWT.
OAuth vs OIDC — Interview Comparison
| OAuth 2.0 | OpenID Connect | |
|---|---|---|
| Purpose | Authorization | Authentication |
| Question | What can you access? | Who are you? |
| Built on | — | OAuth 2.0 |
| Access Token | Yes | Used alongside OIDC for API access |
| ID Token | No | Yes |
| API access | Yes | Via OAuth |
| User login | Not its primary purpose | Yes |
| SSO | Not by itself | Yes |
| Service-to-service | Yes | Usually not needed |
| Special scope | API-specific scopes | openid |
| Typical user flow | Authorization Code + PKCE | Authorization Code + PKCE |
| Machine flow | Client Credentials | Usually not applicable |
Interview Summary
A strong short answer is:
OAuth 2.0 is an authorization framework that controls access to protected APIs using access tokens. OpenID Connect is an authentication layer built on OAuth 2.0 that establishes the user's identity and introduces the ID Token. The access token is intended for the API, while the ID token is intended for the client application. In microservices, OAuth Client Credentials is commonly used for service-to-service access, while OIDC is commonly used when users need to log in or use SSO.
The easiest way to remember:
OpenID Connect
|
v
WHO ARE YOU?
Authentication
|
ID Token
OAuth 2.0
|
v
WHAT CAN YOU ACCESS?
Authorization
|
Access Token
OIDC identifies the user; OAuth authorizes access to resources.