OAuth 2.0, OIDC & Distributed Token Authentication
The Compromised Admin Token That Wouldn't Die
Test your architecture intuition: Pitch a 7-axis solution, survive two aggressive reviewer objections, and inspect the staff-level Teacher Gold Answer.
1. What It Is & Why It Exists
The Core Problem: Delegated Authorization vs. Authentication
In distributed architectures, microservices must answer two fundamental security questions:
- Authentication (AuthN - "Who are you?"): Verifying identity. Solved by OpenID Connect (OIDC), an identity layer built on top of OAuth 2.0 that provides standardized ID Tokens (
id_token). - Authorization (AuthZ - "What permissions do you have?"): Delegating access rights to third parties without sharing user passwords. Solved by OAuth 2.0, which issues scoped Access Tokens (
access_token).
Synthesizing vector architecture diagram...
2. OAuth 2.0 Authorization Code Flow with PKCE
For Single-Page Applications (SPAs) and mobile clients that cannot securely store client secrets, PKCE (Proof Key for Code Exchange - RFC 7636) is mandatory to prevent authorization code interception attacks. The OAuth security best practice (RFC 9700) requires PKCE for public clients and recommends it for confidential clients too; the OAuth 2.1 draft requires it for every authorization code flow.
Synthesizing vector architecture diagram...
3. Token Formats & Cryptographic Comparison
Comprehensive Comparison Matrix
| Format | Structure | Signature / Encryption | Payload Tampering Defense | Revocation Mechanism | Latency Overhead |
|---|---|---|---|---|---|
| Stateful Session ID | Opaque random ID (at least 128 bits from a CSPRNG) | None (Lookup Key) | Server-side storage validation | Immediate (DEL session:uuid) | One network round trip to the session store (e.g. Redis) per RPC |
| JWT (RS256 / EdDSA) | Header.Payload.Signature | Asymmetric Public Key (RS256 / Ed25519) | Cryptographic signature verification | Bloom filter / Redis blocklist / Short TTL | (Local CPU verification) |
| PASETO (v4.public / v4.local) | v4.public.<base64url(payload ‖ sig)>[.<footer>] | v4.public: Ed25519 signature; v4.local: XChaCha20 encryption with a BLAKE2b MAC (no alg header to tamper with) | Signature (public) or authenticated encryption (local), fixed per version | Short TTL + Refresh token rotation | (Local CPU verification) |
| Passkeys / WebAuthn | FIDO2 Authenticator Assertion | ECDSA / RSA Hardware Key | Phishing-resistant challenge-response | Public key de-registration | Native OS / Secure Enclave |
Unlock Complete Architecture & Production Runbooks
You have explored the free architectural preview (~38%). Spend 1 Coin to unlock the remaining 4 production deep-dive sections for a full 24 hours.