OpenID Connect enables clients to authenticate using identity providers. It provides a standardized method for authenticating users and can be used for transmitting user information.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Technical building block: can be automated, integrated, or operated.
Concrete cog in the system that works inside larger relationships.
OpenID Connect is an identity layer on OAuth 2.0 that lets clients verify a person's authentication by an OpenID Provider.
The OpenID Foundation developed OpenID Connect as an identity layer on OAuth 2.0 because OAuth alone does not standardize a statement about a person's authentication. The result was an interoperable protocol for ID tokens and identity claims.
A client sends the person to the OpenID Provider and receives an authorization code. After exchanging it for tokens, the client validates the ID token signature and claims such as issuer, audience, and nonce. The access token is for API access; the ID token describes authentication.
The provider authenticates the person and issues signed tokens containing identity claims.
The JWT confirms authentication to the client and carries standardized claims.
OIDC uses OAuth flows and adds identity semantics; authorization and sign-in remain distinct.
OIDC enables standardized sign-in across clients and identity providers. Flow choice, redirect and token protection, claim mapping, key rotation, and session management require secure configuration.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.