Security
OpenID Connect (OIDC)
How OSTaaS uses OIDC to verify who you are with your identity provider.
OIDC is the standard OSTaaS uses to confirm your identity with providers like Microsoft and Google. It sits on top of OAuth and adds a verifiable identity token.
What OIDC does
- Proves who you are (an ID token) in addition to granting access.
- Lets OSTaaS trust your provider's authentication without ever seeing your password.
The flow, briefly
- You choose a provider and are sent to it to sign in.
- The provider returns a signed identity token to OSTaaS's server.
- OSTaaS verifies the token, establishes your session, and drops you on the result screen.
State and nonce values protect the exchange against replay and interception. All verification happens server-side.
Related
Last updated 2026-09-02