Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The difference between OIDC and OAuth boils down to exchanging attribute assertions describing a user as opposed to the delegation of a specific set of allowed actions, as OAuth was intended to do. OIDC and SAML are basically the same thing, with OIDC being a somewhat less frightening and more modern protocol.


Reading the user's profile information _is_ the delegated action. OAuth providers were already doing this prior to OIDC but in incompatible ways. OIDC standardized how that information is requested and returned.


No, the whole point of OIDC is that permission to read your profile is not semantically the same thing as authenticated sign-on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: