Prompt
How do I know if my app needs OAuth, OIDC, or SAML?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
A quick way to think about it:
- OAuth 2.0 = authorization
Use it when your app needs to access a user’s data in another system, or let another app act on a user’s behalf. - OpenID Connect (OIDC) = authentication on top of OAuth 2.0
Use it when your app needs to know who the user is and log them in. - SAML = enterprise single sign-on for browser-based apps
Use it when you need to integrate with corporate identity providers, especially in older enterprise environments.
The simplest decision rule
Choose OIDC if:
- You’re building a modern web app, mobile app, SPA, or API-backed app
- You need login / identity / SSO
- You want the standard, modern protocol for sign-in
Example: “Log in with Google/Microsoft/Okta” for your app.
Choose OAuth 2.0 if:
- You do not need to know the user’s identity
- You only need access to an API or resource
- Your app needs a token to call another service on the user’s behalf
Example: Your app connects to a user’s Dropbox to upload files, but you don’t care who they are beyond permission to access that folder.
Choose SAML if:
- You’re doing enterprise SSO with a browser app
- Your customer specifically requires SAML
- You need compatibility with legacy IdPs and enterprise procurement/security requirements
Example: A B2B SaaS product that must support “Sign in with Okta/ADFS/Ping Identity” for corporate customers.
Important nuance: OAuth is not for login by itself
A common mistake is using OAuth as “login.” OAuth alone tells you what an app is allowed to do, not who the user is.
If you need login, use OIDC, not plain OAuth.
Practical examples
1) “Users sign into my app”
- Best fit: OIDC
- If enterprise customers require it: SAML may also be needed
2) “My app calls Google Drive API on behalf of the user”
- Best fit: OAuth 2.0
- If you also want login: OIDC + OAuth together
3) “My enterprise customer wants SSO with their IdP”
- Best fit: SAML if that’s what their IdP supports/requires
- Otherwise OIDC is often preferred if available
4) “I have a backend service talking to another API”
- Best fit: OAuth 2.0 client credentials flow if no user is involved
- OIDC usually isn’t needed
Rule of thumb by app type
- Consumer app / modern web app / mobile app → OIDC
- API access / delegated authorization → OAuth 2.0
- Enterprise SSO / legacy IdP compatibility → SAML
- Need both login and API access → OIDC + OAuth
If you’re choosing for a new product
If there’s no external constraint, the usual default is:
- OIDC for sign-in
- OAuth 2.0 for API authorization
- Add SAML only if customers need it
If you want, I can give you a decision tree or a “which one should I use?” table based on your exact app type.