josiete.com

Web Security

Authentication vs. authorization: OAuth 2.0, OpenID Connect, and SAML explained with examples

Illustration of an identity receiving access to a gallery, with permission to edit an owned photograph and an unrelated photograph protected

A photo application is a useful place to separate concepts that are often blended together. Imagine that Alice signs in, browses a gallery, and changes the title of a photograph she uploaded. She can see one of Bob’s photographs, but cannot edit it. What did each step establish?

The sign-in established Alice’s identity. The decision to edit each photograph applied rules to an action and a specific resource. OAuth 2.0, OpenID Connect (OIDC), and SAML solve different parts of that problem. Keeping their boundaries clear avoids two common mistakes: treating a token as unlimited authorization, and treating an identity assertion as a credential for every API.