Identity & Access
OpenID Connect
OpenID Connect Core
Community
Global
OpenID Foundation
Since 2014
An identity layer on top of OAuth 2.0: the ID token carries verified claims about who the user is, alongside the access token that says what they may do.
Its certification programme is the practical part. Where a control requires federated identity, pointing at a certified implementation is a shorter conversation than describing your own.
At a glance
- Category
- Identity & Access
- Jurisdiction
- Global
- Governance
- OpenID Foundation
- Status
- OpenID Connect Core 1.0; widely certified
- First released
- 2014
Links
Related frameworks
Other entries under Identity & Access.
- XACML: eXtensible Access Control Markup Language
- SAML: Security Assertion Markup Language
- OAuth 2.0: OAuth 2.0 Authorization Framework
- SCIM: System for Cross-domain Identity Management
See OpenID Connect in context
Open the interactive Data Landscape for Regulation to compare OpenID Connect against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.