Configure OIDC SSO

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/37

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 11:18 AM on 12/9/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

38 Terms

1
New cards

What is OpenID Connect (OIDC)?

An identity layer built on top of OAuth 2.0 that provides user authentication and federated Single Sign-On (SSO).

2
New cards

What role does OAuth 2.0 play in authentication?

OAuth 2.0 provides authorization, allowing an authenticated user to grant a client application access to protected resources using an Access Token.

3
New cards

What does an ID Token issued by OIDC contain?

It contains user identity, authentication timestamps, the issuer (Okta), and other claims like email and name.

4
New cards

What is the purpose of an Access Token in OAuth 2.0?

An Access Token is used to access protected APIs/resources and proves that the application has authorization, along with the granted scopes and user context.

5
New cards

What are some OAuth Grant Types for confidential clients?

Confidential clients can use Authorization Code Flow with Client Secret and Client Credentials Flow.

6
New cards

What must you configure before integrating an OIDC app in Okta?

You must configure an Authorization Server, including scopes, claims, and access policies.

7
New cards

What does the Redirect URI do in OIDC Integration?

It is where Okta sends the authentication response and ID Token.

8
New cards

What information is required to integrate an OIDC app in Okta?

Redirect URI, Initiate Login URI, Client ID, and Client Secret.

9
New cards

What is the role of the Client Secret?

The Client Secret is used for confidential client authentication and is stored securely.

10
New cards

What must be configured in WordPress when integrating via miniOrange?

Client ID, Client Secret, Okta Authorization Server URL, and endpoints (issuer, token, authorize).

11
New cards

What does a successful Redirect URI signify?

It receives successful authentication responses from the Okta Authorization Server.

12
New cards

What is the difference between ID Token and Access Token?

ID Token proves the user's identity while the Access Token proves the app's permissions.

13
New cards

What does Okta act as in the OIDC and OAuth 2.0 process?

Okta acts as the Authorization Server and Identity Provider (IdP).

14
New cards
anki_oidc_sso = """
15
New cards
What does OIDC provide?
User authentication and federated single sign on.
16
New cards
What protocol does OIDC extend?
OAuth 2.0.
17
New cards
Who is the Identity Provider IdP when using OIDC with Okta?
Okta.
18
New cards
What does OAuth 2.0 provide?
Authorization to access protected resources.
19
New cards
What token is used for user authentication in OIDC?
The ID Token.
20
New cards
What token is used for authorization in OAuth 2.0?
The Access Token.
21
New cards
What format is the ID Token in?
A JSON Web Token JWT.
22
New cards
Who issues the ID Token and Access Token?
The Okta authorization server.
23
New cards
What does the ID Token prove?
That the user has been authenticated.
24
New cards
What does the Access Token prove?
That the application has been authorized to access resources with specific scopes.
25
New cards
What does the resource server use to validate authorization?
The Access Token.
26
New cards
What are OAuth grant types used for?
Obtaining an Access Token.
27
New cards
What is a confidential client?
An application that can securely store a client secret.
28
New cards
What must be configured before integrating an OIDC app?
An authorization server with scopes claims and access policies.
29
New cards
Can you use the default authorization server for OIDC?
Yes the default server can be used.
30
New cards
What is the redirect URI?
The URI where Okta sends the authentication response and ID Token.
31
New cards
What is the initiate login URI?
The URI where the OIDC login process begins.
32
New cards
What does the application need from Okta to complete OIDC setup?
The client ID and client secret.
33
New cards
Why is the client secret only for confidential clients?
Because it must be stored securely on a back end server.
34
New cards
Where are the client ID and secret configured?
Inside the external OIDC application such as WordPress.
35
New cards
In OIDC who authenticates the user?
Okta as the Identity Provider.
36
New cards
In OAuth who authorizes access to resources?
The resource server using the Access Token.
37
New cards
"""
38
New cards