Prompt
Do I need OIDC instead of OAuth for sign in?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Usually, yes — if your goal is “sign in” / authentication, you want OpenID Connect (OIDC), not plain OAuth.
Short version
- OAuth 2.0 = authorization
Used to let an app access an API on a user’s behalf. - OIDC = authentication on top of OAuth 2.0
Used to prove who the user is and to log them in.
Why this matters
OAuth by itself does not tell your app:
- who the user is
- whether they are authenticated
- their identity details
OIDC adds:
- an ID token
- standard claims like user identity
- a standardized login flow
If you’re building…
- “Sign in with Google/Microsoft/etc.” → use OIDC
- Accessing an API with user consent → use OAuth
- Both login and API access → use OIDC + OAuth together
(common in real apps)
Rule of thumb
If the question is “Can this person log in?” → OIDC
If the question is “Can this app call this API?” → OAuth
If you want, I can also show you a simple diagram of how OIDC differs from OAuth in a login flow.