Configure OIDC SSO

โญ Configure OIDC SSO


๐Ÿ“Œ What Is OIDC?

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, providing:

  • User authentication

  • Federated Single Sign-On (SSO)

OIDC allows applications (clients) to verify a userโ€™s identity using ID Tokens issued by an Identity Provider (IdP)โ€”in this case, Okta.


๐Ÿ“Œ What Is OAuth 2.0?

OAuth 2.0 provides authorization, not authentication.

It allows an authenticated user to grant a client application access to protected resources using an Access Token.


๐Ÿ“Œ OIDC + OAuth 2.0: How They Work Together

OIDC and OAuth 2.0 operate together during an SSO transaction:

๐Ÿ” 1. OIDC Authentication

  • OIDC issues an ID Token (JWT format).

  • The ID Token contains:

    • User identity (subject)

    • Authentication timestamps

    • Issuer (Okta)

    • Other claims like email, name, etc.

Flow:

  1. User signs in to the OIDC app.

  2. Okta authenticates them.

  3. Okta Authorization Server issues an ID Token.

  4. Application confirms identity using the ID Token.


๐Ÿ”‘ 2. OAuth 2.0 Authorization

OAuth issues an Access Token used to access protected APIs/resources.

The Access Token proves:

  • The application has authorization

  • The scopes granted

  • The user context

Flow:

  1. After authentication, Okta issues the Access Token.

  2. Application uses the token to call the resource server/API.

  3. Resource server validates the token before allowing access.


๐Ÿ“Œ OAuth Grant Types (Flows)

OAuth supports multiple flows depending on the app type:

Confidential Clients

Secure apps (server-side) that can safely store a client secret.

Such clients can use flows like:

  • Authorization Code Flow with Client Secret

  • Client Credentials Flow


๐Ÿ“Œ Before Integrating an OIDC App

You must configure an Authorization Server in Okta:

Configure:

  • Scopes (e.g., openid, profile, email)

  • Claims (data included in ID token or Access Token)

  • Access policies (who can get what scopes)

You can use the default Okta Authorization Server, or create a custom one.


๐Ÿ“Œ Integrating an OIDC App Through the OIN

When adding an OIDC application from the Okta Integration Network:

You must configure:

1. Redirect URI

Where Okta sends the authentication response and ID Token.

Example:

https://example-app.com/oauth2/callback

2. Initiate Login URI

Where the user should be redirected to start the OIDC login process.

3. Client ID & Client Secret

  • Okta generates these for the application

  • They must be configured in the external app

The application uses:

  • Client ID โ†’ To identify itself to Okta

  • Client Secret โ†’ For confidential client authentication


๐Ÿ“Œ Example: Integrating WordPress Using miniOrange (OIDC)

When integrating WordPress through the OIN using the miniOrange plugin:

In Okta you configure:

  • Redirect URI

  • Initiate Login URI

  • Authorization Server scopes & claims

In WordPress (miniOrange plugin):

  • Enter:

    • Client ID

    • Client Secret

    • Okta Authorization Server URL

    • Endpoints (issuer, token, authorize)


๐Ÿ“Œ Key Concepts for Exams

  • OIDC provides authentication โ†’ ID Token

  • OAuth 2.0 provides authorization โ†’ Access Token

  • ID Token proves the userโ€™s identity

  • Access Token proves the appโ€™s permissions

  • Redirect URI receives successful authentication responses

  • Client Secret is used only by confidential clients

  • Okta acts as the Authorization Server and Identity Provider (IdP)