ID tokens and access tokens in OIDC

Coming soon
IntermediateDifficulty: Intermediate
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 3 · Mechanisms · T04.04

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

How can you distinguish proof of sign-in from permission to call an API?

What we will work through

Distinguish proof of sign-in from permission to call an API.

Before you begin

Previously covered: OAuth participants and delegated access; Inside a JWT: header, payload, and signature.

Articles

Color theme

Language

Home