Glossary

OPENID CONNECT / OIDC
defined.

An identity layer built on top of OAuth 2.0 that adds authentication and a standardised user info endpoint.

A–Z

What is OpenID Connect (OIDC)?

OIDC adds the id_token (a signed JWT representing the authenticated user) and the /userinfo endpoint. Common bugs: failing to validate aud, iss, nonce; trusting unsigned discovery documents; or accepting unsigned id_token in implicit flow.

Where this shows up.

See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.

Test for this in your stack

BOOK A FREE
scoping call.

30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.