Identity & Access

OpenID Connect

OpenID Connect Core

Community Global OpenID Foundation Since 2014

An identity layer on top of OAuth 2.0: the ID token carries verified claims about who the user is, alongside the access token that says what they may do.

Its certification programme is the practical part. Where a control requires federated identity, pointing at a certified implementation is a shorter conversation than describing your own.

At a glance

Category
Identity & Access
Jurisdiction
Global
Governance
OpenID Foundation
Status
OpenID Connect Core 1.0; widely certified
First released
2014

Links

Related frameworks

Other entries under Identity & Access.

See OpenID Connect in context

Open the interactive Data Landscape for Regulation to compare OpenID Connect against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.