← Back to Article List         
OAuth 2.0 vs OpenID Connect

OAuth 2.0 vs OpenID Connect

Published on 29 Sep 2026     9 min read Microservices
Authentication & Security

OAuth 2.0 vs OpenID Connect (OIDC)

The simplest difference is:

OAuth 2.0 = Authorization — What are you allowed to access?
OpenID Connect = Authentication — Who are you?

OpenID Connect is built on top of OAuth 2.0.


1. Basic Difference

OAuth 2.0
    |
    v
Authorization
    |
    v
"What can you access?"


OpenID Connect
    |
    v
Authentication
    |
    v
"Who are you?"

For example:

OAuth:
"Syed can read orders."

OIDC:
"This authenticated user is Syed."

2. What Is OAuth 2.0?

OAuth 2.0 is an authorization framework.

Its primary purpose is to allow a client application or service to obtain controlled access to a protected resource/API.

Example:

Angular
   |
   | Access Token
   v
Order API

The token might grant:

orders.read
orders.create

The API uses those permissions to determine what operations are allowed.


3. What Is OpenID Connect?

OpenID Connect is an authentication protocol/identity layer built on OAuth 2.0.

Its purpose is to allow an application to establish the identity of the authenticated user.

Example:

User
  |
  | Login
  v
Identity Provider
  |
  | ID Token
  v
Angular Application

The application can establish identity information such as:

User ID
Name
Email

depending on the claims provided.


4. Most Important Difference — Tokens

This is one of the most important interview points.

OAuth 2.0

Primarily uses an:

Access Token

The access token is intended for the API/resource server.

Client
   |
   | Access Token
   v
Web API

OpenID Connect

Introduces an:

ID Token

The ID token is intended for the client application.

Identity Provider
       |
       | ID Token
       v
Client Application

OIDC flows can also obtain an access token when the application needs to call an API.


5. Access Token vs ID Token

Access Token ID Token
Associated with OAuth 2.0 Introduced by OIDC
Used for API access Used to communicate authentication information to client
Sent to API Consumed by client
Represents delegated/application authorization Represents authenticated user/session claims
Audience normally resource/API Audience normally client application
Can contain scopes/roles/permissions Contains identity/authentication claims

Remember:

Access Token
     |
     v
    API


ID Token
     |
     v
   Client

6. Example

Suppose you have:

Angular
   +
ASP.NET Core Web API
   +
Microsoft Entra ID

The user logs in.

User
  |
  v
Angular
  |
  | Login
  v
Identity Provider
  |
  | Authenticate
  v
Authorization Code
  |
  v
Angular
  |
  | Code + PKCE
  v
Identity Provider

The application can receive/use:

             Identity Provider
                    |
          +---------+---------+
          |                   |
          v                   v
      ID Token          Access Token
          |                   |
          v                   v
       Angular             Web API

The distinction is:

ID Token
   ↓
Who authenticated?


Access Token
   ↓
What API access is granted?

7. Example ID Token

Conceptually:

{
  "sub": "1001",
  "name": "Syed",
  "email": "syed@example.com",
  "iss": "https://identity.example.com",
  "aud": "angular-client"
}

The client uses the ID token as part of establishing the authenticated user's identity/session.


8. Example Access Token

Conceptually:

{
  "sub": "1001",
  "aud": "order-api",
  "scope": "orders.read orders.create",
  "iss": "https://identity.example.com",
  "exp": 1790690000
}

The API uses it to authorize requests.

For example:

GET /api/orders
Authorization: Bearer <access_token>

9. Important Rule

Don't use the ID token as the credential for calling your API.

Wrong:

Angular
   |
   | ID Token
   v
Order API

Use:

Angular
   |
   | Access Token
   v
Order API

The two tokens have different intended recipients and purposes.


10. openid Scope

OIDC uses the special:

openid

scope.

For example:

openid
profile
email
orders.read

Conceptually:

openid
   |
   +--> Request OpenID Connect authentication

profile
   |
   +--> Request standard profile information

email
   |
   +--> Request email claims

orders.read
   |
   +--> Request API authorization

The presence of openid makes the authorization request an OpenID Connect request.


11. OAuth in Microservices

OAuth is especially important for API authorization and service-to-service communication.

For example:

Order Service
     |
     | Client Credentials
     v
Authorization Server
     |
     | Access Token
     v
Order Service
     |
     | Access Token
     v
Payment Service

Here:

No user login
No ID Token required

Order Service is acting as itself.

Therefore:

OAuth 2.0 Client Credentials

is appropriate.


12. OIDC in Microservices

OIDC becomes relevant when there is a user authentication requirement.

For example:

User
  |
  | Login
  v
Angular
  |
  v
Identity Provider

OIDC authenticates the user.

Then the client uses an OAuth access token to call APIs:

User
  |
  v
Angular
  |
  | Access Token
  v
API Gateway
  |
  v
Order Service

13. Complete Real-World Architecture

Consider:

                   Microsoft Entra ID
                         ^
                         |
                 OAuth + OpenID Connect
                         |
                         |
User -----------> Angular Application
                         |
                         | Access Token
                         v
                    API Gateway
                         |
                         v
                    Order Service
                         |
                         | OAuth
                         | Client Credentials
                         |
                         | Service Access Token
                         v
                   Payment Service

There are two different scenarios here.

User authentication

User
 ↓
OIDC
 ↓
Identity Provider
 ↓
Authenticated User

API authorization

Angular
 ↓
OAuth Access Token
 ↓
Order API

Service-to-service authorization

Order Service
 ↓
OAuth Client Credentials
 ↓
Access Token
 ↓
Payment Service

14. OAuth Doesn't Mean "Login"

A common interview mistake is saying:

"OAuth is used to authenticate the user."

OAuth 2.0 itself is primarily about authorization.

OIDC adds standardized authentication on top of OAuth.

OAuth
   ↓
Authorization


OIDC
   ↓
Authentication

15. OAuth vs OIDC vs JWT

These three terms are frequently confused.

Technology What is it? Purpose
OAuth 2.0 Authorization framework API/resource authorization
OpenID Connect Identity/authentication protocol User authentication
JWT Token format Represent signed claims

So:

OAuth 2.0
    !=
OIDC
    !=
JWT

But they often work together.


16. How They Work Together

                 OAuth 2.0
                     |
              Authorization
                     |
                     +---- Access Token
                     |
                     |
              OpenID Connect
                     |
               Authentication
                     |
                     +---- ID Token

The ID token is a JWT.

OAuth access tokens may also be JWTs, depending on the authorization server.


17. Simple Real-Life Example

Think about entering an office.

OpenID Connect

Security asks:

Who are you?

Name: Syed
Employee ID: 1001

That's authentication.

OAuth

After identifying you, the system determines:

What can you access?

Reception       ✓
Development     ✓
Finance         ✗
Server Room     ✗

That's authorization.

Therefore:

OIDC
=
Who are you?


OAuth
=
What can you access?

18. Advantages of OAuth 2.0

  • Standardized API authorization
  • Supports fine-grained permissions
  • Access tokens can be short-lived
  • Users don't give their passwords to resource APIs
  • Supports service-to-service authentication/authorization
  • Works well with distributed systems
  • Supports multiple authorization flows
  • Centralizes authorization infrastructure

19. Advantages of OIDC

  • Standardized user authentication
  • Supports Single Sign-On
  • Supports federated identity
  • Provides ID Tokens
  • Standard identity claims
  • Integrates naturally with OAuth
  • Supported by major identity providers

Examples include:

Microsoft Entra ID
Google
Keycloak
Auth0
Duende IdentityServer

20. Disadvantages

Both OAuth/OIDC introduce additional concepts and infrastructure:

Identity Provider
Client Registration
Redirect URI
Scopes
Claims
Access Tokens
ID Tokens
Refresh Tokens
PKCE
Token Validation
Key Rotation

Misconfiguration can also create security problems.

For production applications, use established OAuth/OIDC libraries rather than implementing these protocols yourself.


21. Key Points

For interviews, remember these:

  1. OAuth 2.0 is primarily for authorization.
  2. OIDC is for authentication/identity.
  3. OIDC is built on OAuth 2.0.
  4. OAuth uses Access Tokens to access protected APIs.
  5. OIDC introduces the ID Token.
  6. ID Token → intended for the client.
  7. Access Token → intended for the API.
  8. openid indicates an OIDC request.
  9. Authorization Code + PKCE is commonly used for interactive clients.
  10. Client Credentials is commonly used for service-to-service access.
  11. OAuth is not the same as JWT.
  12. OIDC is not the same as JWT.
  13. JWT is a token format.
  14. OIDC ID Tokens are JWTs.
  15. OAuth access tokens may be JWTs, but don't have to be.

22. Interview Questions and Answers

Q1. OAuth 2.0 vs OpenID Connect?

Answer:

OAuth 2.0 is an authorization framework used to grant clients access to protected resources through access tokens.

OpenID Connect is an authentication protocol built on OAuth 2.0 that allows applications to authenticate users and obtain identity information, including through an ID Token.


Q2. Which is used for authentication?

OpenID Connect.

OIDC
 ↓
Authentication

Q3. Which is used for authorization?

OAuth 2.0.

OAuth
 ↓
Authorization

Q4. What token does OAuth use for API access?

An:

Access Token

Client
  |
  | Access Token
  v
API

Q5. What token does OpenID Connect introduce?

An:

ID Token

Identity Provider
       |
       | ID Token
       v
Client

Q6. Should an ID Token be sent to a Web API?

Normally, no.

Use an access token when calling the API:

Client
   |
   | Access Token
   v
Web API

The ID token is intended for the client application.


Q7. Can OAuth be used without OpenID Connect?

Yes.

For example, service-to-service communication:

Order Service
      |
      | OAuth Client Credentials
      v
Authorization Server
      |
      | Access Token
      v
Payment Service

There is no user authentication requirement, so OIDC is unnecessary for that specific interaction.


Q8. Can OpenID Connect exist without OAuth?

OIDC is built on top of OAuth 2.0, so it uses OAuth's authorization infrastructure and extends it with identity/authentication capabilities.


Q9. Is an Access Token always JWT?

No.

An OAuth access token can be:

JWT

or an opaque/reference token, depending on the authorization server.


Q10. Is an ID Token a JWT?

Yes. The OIDC ID Token is represented as a JWT.


OAuth vs OIDC — Interview Comparison

  OAuth 2.0 OpenID Connect
Purpose Authorization Authentication
Question What can you access? Who are you?
Built on — OAuth 2.0
Access Token Yes Used alongside OIDC for API access
ID Token No Yes
API access Yes Via OAuth
User login Not its primary purpose Yes
SSO Not by itself Yes
Service-to-service Yes Usually not needed
Special scope API-specific scopes openid
Typical user flow Authorization Code + PKCE Authorization Code + PKCE
Machine flow Client Credentials Usually not applicable

Interview Summary

A strong short answer is:

OAuth 2.0 is an authorization framework that controls access to protected APIs using access tokens. OpenID Connect is an authentication layer built on OAuth 2.0 that establishes the user's identity and introduces the ID Token. The access token is intended for the API, while the ID token is intended for the client application. In microservices, OAuth Client Credentials is commonly used for service-to-service access, while OIDC is commonly used when users need to log in or use SSO.

The easiest way to remember:

        OpenID Connect
              |
              v
        WHO ARE YOU?
        Authentication
              |
          ID Token


          OAuth 2.0
              |
              v
     WHAT CAN YOU ACCESS?
        Authorization
              |
        Access Token

OIDC identifies the user; OAuth authorizes access to resources.