Configure OIDC SSO
โญ Configure OIDC SSO
๐ What Is OIDC?
OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, providing:
User authentication
Federated Single Sign-On (SSO)
OIDC allows applications (clients) to verify a userโs identity using ID Tokens issued by an Identity Provider (IdP)โin this case, Okta.
๐ What Is OAuth 2.0?
OAuth 2.0 provides authorization, not authentication.
It allows an authenticated user to grant a client application access to protected resources using an Access Token.
๐ OIDC + OAuth 2.0: How They Work Together
OIDC and OAuth 2.0 operate together during an SSO transaction:
๐ 1. OIDC Authentication
OIDC issues an ID Token (JWT format).
The ID Token contains:
User identity (subject)
Authentication timestamps
Issuer (Okta)
Other claims like email, name, etc.
Flow:
User signs in to the OIDC app.
Okta authenticates them.
Okta Authorization Server issues an ID Token.
Application confirms identity using the ID Token.
๐ 2. OAuth 2.0 Authorization
OAuth issues an Access Token used to access protected APIs/resources.
The Access Token proves:
The application has authorization
The scopes granted
The user context
Flow:
After authentication, Okta issues the Access Token.
Application uses the token to call the resource server/API.
Resource server validates the token before allowing access.
๐ OAuth Grant Types (Flows)
OAuth supports multiple flows depending on the app type:
Confidential Clients
Secure apps (server-side) that can safely store a client secret.
Such clients can use flows like:
Authorization Code Flow with Client Secret
Client Credentials Flow
๐ Before Integrating an OIDC App
You must configure an Authorization Server in Okta:
Configure:
Scopes (e.g., openid, profile, email)
Claims (data included in ID token or Access Token)
Access policies (who can get what scopes)
You can use the default Okta Authorization Server, or create a custom one.
๐ Integrating an OIDC App Through the OIN
When adding an OIDC application from the Okta Integration Network:
You must configure:
1. Redirect URI
Where Okta sends the authentication response and ID Token.
Example:
https://example-app.com/oauth2/callback
2. Initiate Login URI
Where the user should be redirected to start the OIDC login process.
3. Client ID & Client Secret
Okta generates these for the application
They must be configured in the external app
The application uses:
Client ID โ To identify itself to Okta
Client Secret โ For confidential client authentication
๐ Example: Integrating WordPress Using miniOrange (OIDC)
When integrating WordPress through the OIN using the miniOrange plugin:
In Okta you configure:
Redirect URI
Initiate Login URI
Authorization Server scopes & claims
In WordPress (miniOrange plugin):
Enter:
Client ID
Client Secret
Okta Authorization Server URL
Endpoints (issuer, token, authorize)
๐ Key Concepts for Exams
OIDC provides authentication โ ID Token
OAuth 2.0 provides authorization โ Access Token
ID Token proves the userโs identity
Access Token proves the appโs permissions
Redirect URI receives successful authentication responses
Client Secret is used only by confidential clients
Okta acts as the Authorization Server and Identity Provider (IdP)