OpenID Connect (OIDC)
An authentication layer built on OAuth 2.0 that lets an application verify who the user is, through a signed ID token issued by an OpenID Provider.
OpenID Connect (OIDC) is an identity layer on top of OAuth 2.0, published by the OpenID Foundation as OpenID Connect Core 1.0. OAuth on its own delegates access to resources but does not tell an application who the user is. OIDC adds that: after the user signs in at the OpenID Provider (the identity provider), the application, called the relying party, receives an ID token alongside the usual access token. The ID token is a signed JSON Web Token stating who authenticated, which provider issued the statement, which application it is for, and when it expires.
OIDC and SAML solve the same federation problem and are often both supported by one identity provider. SAML carries XML assertions and is long established in enterprise browser single sign-on; OIDC carries JSON tokens and is commonly chosen for mobile apps, single-page applications and application interfaces. The relying party should not treat an OAuth access token as proof of who the user is.
Exam relevance: questions in this area tend to turn on the split between authorisation and authentication. A scenario about an application needing to know who signed in points to OpenID Connect; one about granting access to data without sharing a password points to OAuth. Candidates are expected to identify the ID token as the OIDC element that carries identity.