What is the difference between SAML, OAuth 2.0 and OpenID Connect?
Suggested answer
They answer different questions, and conflating them is the source of a lot of muddled design.
• SAML is an authentication protocol. It answers “who is this user?” by having an identity provider send a signed XML assertion to a service provider. It is the workhorse for enterprise web single sign-on.
• OAuth 2.0 is an authorisation protocol. It answers “may this application act on this user's behalf, and how far?” It issues tokens with scopes. On its own it says nothing reliable about who the user is.
• OpenID Connect is a thin identity layer on top of OAuth 2.0. Requesting the openid scope adds a signed identity token with standard claims, plus a UserInfo endpoint and a discovery document. It is how you get authentication out of an OAuth exchange properly.
In Salesforce terms: SAML single sign-on settings for inbound enterprise authentication, Auth. Providers for inbound social and OpenID Connect identity, and connected apps for outbound — Salesforce as a SAML identity provider or as an OpenID Connect provider, and as the authorisation server for API integrations.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.