OpenID Connect is an identity layer on top of OAuth: the authorization server also returns an ID token, a signed JWT whose required claims say who issued it (iss), who signed in (sub), which client it was issued to (aud), and when it was issued (iat) and expires (exp). If the client sent a nonce, the token carries it back so the client can tie it to its own sign-in request. Clients usually find the provider’s endpoints and signing keys through its discovery document at /.well-known/openid-configuration (OpenID Connect Discovery), and the current security guidance, RFC 9700, requires PKCE on the authorization code flow for public clients such as browser and mobile apps and recommends it for all others. The ID token and its checks are in OpenID Connect Core.

In an FDE interview

You rarely get to choose between OIDC and SAML: the customer’s identity team decides, and theirs may be set up only for . Okta’s postings, as of September 2026, list both. Source 1Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 2Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 3Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting In designing sign-in through a large customer’s identity provider, a strong candidate supports both behind one broker, so each customer connection is configuration rather than code, and then says what the OIDC path must check: the signature against the provider’s published keys, then issuer, audience, expiry and nonce.

Pin the accepted algorithms, refetch the provider’s keys when a token names a key ID (kid) you do not have, and check that the issuer is the one configured for this customer: with a multi-tenant identity provider, a valid token from another company’s tenant would otherwise sign someone into this customer’s workspace. Key the user on the issuer and sub pair, never on email, because OIDC Core guarantees only that sub is unique and stable within one issuer, and people change email addresses. Never send the ID token to your API as a bearer token; that is what the access token is for.

The lesson Identity and network in someone else’s environment compares OIDC and SAML sign-in.

GlossaryOAuthA standard for granting an application limited, revocable access to resources on a user’s behalf without sharing passwords.More on OAuthGlossarySAMLAn XML-based standard for exchanging authentication assertions between an identity provider and an application.More on SAMLGlossaryForward deployed engineerA software engineer who builds and ships production systems inside a customer’s problem and environment, accountable to that customer’s outcome.More on Forward deployed engineer