Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OAuth 2.0 is for authorization: it lets a client obtain delegated access to a protected resource. OpenID Connect (OIDC) adds a standard identity layer for user sign-in. In a token-based system, an authorization server issues tokens, and the resource server checks whether an access token permits the requested access. IdentityServer4 is one historical implementation of these protocols—not a protocol itself—and its current support and licensing status should be verified before choosing it.

What is the difference between OAuth 2.0 and OpenID Connect?

OAuth 2.0 addresses authorization: a client requests access to a resource, potentially with a user’s permission. It does not, by itself, define a standard way for the client to establish who signed in. OIDC builds on OAuth 2.0 and standardizes identity behavior, including the openid scope, ID tokens, provider discovery metadata, and a UserInfo endpoint. Microsoft’s protocol overview and its OIDC guide describe those roles.

Four responsibilities are useful to keep distinct, even if a deployment combines some of them in one system:

  • Authorization server: issues tokens.
  • Client: requests tokens and, in an OIDC sign-in, uses identity information to establish a user session.
  • Resource owner: often the end user who grants access to data.
  • Resource server: hosts the protected resource and decides whether a presented access token is acceptable.

OIDC discovery metadata identifies provider endpoints and signing keys. Use the discovery document for the issuer you actually trust; endpoint URLs for one provider, such as Microsoft Entra, are not universal URLs for other identity providers. Microsoft’s OIDC documentation explains its provider metadata.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is the difference between an access token and an ID token?

Token names indicate their intended recipient and purpose. Do not use one type in place of another.

Token Intended use Where it is consumed Security consideration
Access token Represents granted access to a resource. The resource server, such as an API, checks it. Its format and claims can vary by provider and resource. A client should not assume every access token is a readable JWT or inspect tokens issued for APIs it does not own.
ID token Communicates authentication and identity claims in OIDC. The client uses it to establish sign-in; it is not an API access token. Do not present it to an API as though it grants resource access.
Refresh token Allows a client to request new tokens from the authorization server. The authorization server handles the request. Treat it as a sensitive credential and protect it as a secret.

Microsoft notes that token formats and claims vary, and that tokens for its services can have special or encrypted formats. Applications should rely on the provider’s supported libraries and the token’s intended use rather than assume they can parse every token. Microsoft’s tokens and claims overview provides further detail.

Which OAuth flow should I use?

Choose according to whether a user is involved, what kind of client is making the request, and which resource the token must reach. The table reflects Microsoft’s current platform guidance; individual providers and applications may have additional requirements.

Use case Flow to consider What it is for
User sign-in OIDC authorization code flow Provides the OIDC identity layer so the client can establish user sign-in.
Delegated user access Authorization code with PKCE, where supported and appropriate to the client Obtains access to a resource in a user context. Microsoft recommends authorization code with PKCE for delegated user access in web applications.
Application access with no user Client credentials Lets an application act on its own behalf for service-to-service access, rather than on behalf of a signed-in user.
New single-page application on Microsoft’s identity platform Authorization code flow Microsoft recommends this rather than implicit flow for new SPAs, citing browser changes affecting third-party cookies and security guidance.

Microsoft’s recommendation about implicit flow is platform guidance, not a claim that every OAuth deployment behaves identically. Its documentation says, “We strongly recommend that all new applications use the authorization code flow that now supports single-page apps in place of the implicit flow.” The implicit grant guidance gives the context. For supported Microsoft identity-platform applications, Microsoft also recommends using its MSAL libraries rather than hand-crafting token acquisition. Protocol documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should an API validate a bearer access token?

An API should validate the access token presented to it; it should not redirect an API caller to an identity provider to obtain a replacement token. For JWT access tokens, validation should use trusted public signing keys and check the issuer, audience, expiry, and application-specific authorization claims that matter to the API. A valid signature alone does not prove that the token was issued for this API or that the caller may perform the requested operation. Microsoft’s ASP.NET Core JWT bearer guidance covers API configuration and validation.

  1. Trust the issuer: configure the API for the expected identity provider and use that provider’s discovery metadata or a maintained protocol library to obtain trusted signing-key information. Do not copy endpoint or key URLs from an unrelated provider. OIDC discovery guidance
  2. Check token suitability: verify that the issuer, audience, and expiry meet the API’s requirements. Reject a token intended for a different resource, even if its signature is valid.
  3. Apply application authorization: check relevant scopes, roles, tenant membership, or other policies for the requested operation. Authentication of a token and authorization to perform an action are separate decisions.
  4. Keep credentials and state safe: protect refresh tokens and other credentials as secrets. Avoid putting sensitive data directly in OAuth state; Microsoft’s guidance recommends using an identifier that refers to data held in browser storage. Microsoft protocol guidance

Prefer maintained protocol libraries over hand-written token exchanges and validation. If an API accepts a token format other than JWT, do not impose JWT parsing assumptions; use the provider’s supported validation approach. Microsoft cautions against depending on the internal format of tokens issued to its services. Tokens and claims overview

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is IdentityServer4, and is it still supported?

IdentityServer4 is an implementation of OAuth and OIDC for ASP.NET Core, not a competing authentication protocol. Microsoft’s .NET microservices architecture material describes integrating it as an OpenID Connect provider, including adding it to dependency injection and the HTTP pipeline so an ASP.NET Core service can expose OAuth/OIDC endpoints and issue tokens. Microsoft’s .NET microservices security material describes that integration pattern.

The available Microsoft architecture material does not establish IdentityServer4’s present maintenance or support status. Duende’s current documentation describes Duende IdentityServer as a token-service engine based on OAuth 2.x and OIDC and documents its token endpoint. That is evidence about a related current product; it does not establish IdentityServer4’s support status, the licensing terms for a particular deployment, or a migration path. Verify the relevant project’s current maintainer guidance, version, and license before adopting or continuing either product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

How should you compare token-service implementations?

There is not enough comparable current support, licensing, feature, or cost information here to rank IdentityServer4 against alternatives. For a real evaluation, compare the same dimensions against version-specific documentation from each maintainer:

  • Supported client types and flows, and the protocol features the application needs.
  • Token validation, trusted-key discovery, and signing-key rotation support.
  • Security update policy and maintenance status.
  • Deployment and ongoing operational burden.
  • Licensing and total cost for the intended use.
  • Integration with the application’s framework and identity store.

Keeping the selected solution current with security patches is part of Microsoft’s selection guidance for authentication approaches. ASP.NET Core bearer authentication guidance

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.