Key Insights
This whitepaper explains the main aspects of OAuth and OpenID Connect that every API provider needs to know — including a core distinction many providers get wrong: OAuth is for delegated access only, not authentication, federation, or authorization. It explains how these protocols fit into a broader security program as part of the "Neo-security Stack," and walks through practical concepts like scopes, bearer vs. Holder-of-Key tokens, and the difference between consent and true authorization. After reading this whitepaper, you will have the requisite knowledge needed to begin protecting APIs with OAuth and OpenID Connect.
OAuth 2.0 and OpenID Connect are fundamental to securing your APIs. To protect the data that your services expose, you will need these protocols. They are complicated though, and it is easy to get lost in the hundreds of pages that make up these specifications. To find your way, read on to get a good introduction to these important security standards!
Table of contents
Introduction — 1
OAuth and OpenID Connect in Context — 2
Start with a Secure Foundation — 3
Overview of OAuth — 4
Actors in OAuth — 5
Scopes — 7
Kinds of Tokens — 7
Passing Tokens — 8
Profiles of Tokens — 8
Types of Tokens — 9
JSON Web Tokens — 10
OAuth Flows — 10
Improper and Proper Uses of OAuth — 11
Consent vs. Authorization — 12
Building OpenID Connect Atop OAuth — 12
The User Info Endpoint and OpenID Connect Scopes — 13
Not Backward Compatible with v. 2 — 14
Conclusion — 14



