NOTE
OpenID Connect
Identity layer on OAuth with ID tokens, UserInfo, issuer/audience/nonce validation, and authentication sessions.
This is a historical learning note and may contain outdated or incomplete understanding.
OpenID Connect (OIDC) adds an authentication/identity layer on top of OAuth authorization flows. The authorization server acts as an OpenID Provider and can issue an ID Token describing the authenticated session/user identity.
Clients must validate signature, issuer, audience, time claims, and nonce/state semantics required by the flow. An ID token is for the client to understand authentication; it is not automatically the correct token for calling every resource API.
Use discovery/JWKS/key rotation from the provider contract rather than hard-coding long-lived signing keys.