Understanding OpenID Connect Series
The following blog posts make up my series on OpenID Connect. This is part of the SAML2 vs JWT series.
Read article: Understanding OpenID Connect Series24 articles tagged SAML.
The following blog posts make up my series on OpenID Connect. This is part of the SAML2 vs JWT series.
Read article: Understanding OpenID Connect SeriesIn part 1 and part 2 of Understanding OpenID Connect, core concepts and the first Authentication Flow (Authorization Code Grant Flow) were introduced. In part 3, we look at the remaining Authentication Flows (Implicit Flow and Hybrid Flow) and some other features of the OIDC specification.
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 3This post continues our discussion of OpenID Connect (OIDC). We look at one of the three Authentication Flows defined by the OIDC spec — the Authorization Code Grant Flow.
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 2This post builds upon what we learned about OAuth2 and JWT in previous posts. OpenID Connect will give us the final building block for the JWT-related use cases that this series will explore. The goal of this blog post is to provide a deep understanding of the OpenID Connect spec without having to…
Read article: SAML2 vs JWT: Understanding OpenID Connect Part 1This blog post continues the SAML2 vs JWT series. In the last post, we discussed JSON Web Tokens. Now, we are going to move on to OAuth2 and OpenID Connect, which provides some structure and protocol around the use of JWT. These protocols are used, along with JWT, to build the JWT use cases this…
Read article: SAML2 vs JWT: Understanding OAuth2In our next SAML2 vs JWT post, we are going to use a JWT with a very simple API that is proxied through Apigee Edge Public Cloud. The JWT token will be an OAuth2 access token generated by Azure Active Directory. In the last post in this series, we explored what JSON Web Tokens (JWTs) are and the…
Read article: SAML2 vs JWT: Apigee & Azure Active Directory Integration — A JWT StoryIn this post, we begin our exploration of the JSON Web Token (JWT) specification as part of the SAML v2.0 vs JWT Series. To understand JWT use cases, we must also look at OpenID Connect v1.0, OAuth v2.0, and and a few related specifications — the JWT spec by itself is not very interesting or…
Read article: SAML2 vs JWT: Understanding JSON Web Token (JWT)This post wraps our look at SAML v2.0 Use Cases. The first four use cases are described in “SAML v2.0 vs JWT: SAML2 Web Application SSO Use Cases” and “SAML v2.0 vs. JWT: SAML2 with SOAP Web Services and REST APIs”. The full list of SAML2 vs JWT-related blog posts can be found here.
Read article: SAML v2.0 vs. JWT: SAML2 Single LogoutThis post continues our look at SAML v2.0 Use Cases. The first two use cases are described in “SAML v2.0 vs JWT: SAML2 Web Application SSO Use Cases”. The full list of SAML2 vs JWT-related blog posts can be found here.
Read article: SAML v2.0 vs. JWT: SAML2 with SOAP Web Services and REST APIsThis is a list of all the SAML2 vs JWT related posts I have written. This series explores SAML2 use cases, JWT use cases, the relevant specifications, and explores how the two technologies differ. The reader will see how identity federation technology has evolved over the past fifteen years.
Read article: SAML v2.0 vs. JWT Series