Skip to content

OAuth2/OIDC Federated

OAuth2 and OpenID Connect (OIDC) are foundational protocols for enabling secure, decentralized identity verification in federated access scenarios. In a Zero Trust architecture, federated access allows users to authenticate through a trusted identity provider (IdP) and access multiple service providers (SPs) without re-authenticating, reducing friction while maintaining strict access controls. These protocols underpin modern identity-perimeter architectures by enabling trust delegation, token-based authentication, and standardized identity claims.


Understanding OAuth2 and OIDC

OAuth2: Authorization Framework

OAuth2 is an authorization protocol that enables applications to access resources hosted by web services on behalf of a user. It operates through grant types, such as the client credentials grant for server-to-server communication or the authorization code grant for user-agent flows.

Key Concepts:
- Access Token: A credential representing permissions to access a resource.
- Scope: Defines the granularity of access (e.g., openid, email).
- Token Endpoint: The endpoint where clients request tokens (e.g., /token).

OIDC: Identity Layer

OIDC is an extension of OAuth2 that adds identity verification. It introduces ID tokens (JWTs) containing claims about the user’s identity, such as sub (subject) and iss (issuer). OIDC ensures that the user is who they claim to be, making it critical for federated access.

Key Concepts:
- ID Token: A JWT signed by the IdP, containing user identity claims.
- UserInfo Endpoint: Provides additional user attributes (e.g., name, preferred_username).
- Discovery Endpoint: Allows clients to discover IdP metadata (e.g., /.well-known/openid-configuration).


Federated Access Architecture

Flow Overview

In federated access, a user authenticates with an IdP (e.g., Keycloak) and receives tokens to access SPs. The workflow involves:
1. User Authentication: User logs in to the IdP.
2. Token Issuance: IdP issues an ID token (OIDC) and access token (OAuth2).
3. Resource Access: SP validates tokens and grants access based on claims.

Diagram:

User → [IdP] (Auth) → [IdP] → [SP]  
         ↓                        ↓  
         ID Token (JWT)         Access Token  

Example: Keycloak as IdP

Using Keycloak’s OIDC endpoint:

curl -X POST \
  https://keycloak.example.com/auth/realms/myrealm/protocol/openid-connect/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "client_id=myclient" \
  -d "client_secret=mysecret" \
  -d "grant_type=client_credentials" \
  -d "scope=openid"
Response includes an id_token and access_token.


Integration with IAM and Secrets Management

Keycloak IAM Integration

Keycloak acts as the IdP, issuing tokens via OIDC. SPs validate tokens using the jwks_uri from the discovery endpoint:

curl https://keycloak.example.com/auth/realms/myrealm/.well-known/openid-configuration
This returns the jwks_uri for validating the ID token’s signature.

HashiCorp Vault for Secrets

Vault can securely store client secrets and private keys used in OAuth2 flows. For example:

vault kv put secret/oauth/client \
  client_id=myclient \
  client_secret=mysecret \
  jwks_uri=https://keycloak.example.com/auth/realms/myrealm/.well-known/openid-configuration
Vault’s secrets engine ensures these credentials are encrypted and accessible only to authorized services.


Security Considerations

  1. Token Validation: Always verify the ID token’s signature using the IdP’s public key.
  2. Scope Enforcement: Ensure SPs only use the scopes granted in the access token.
  3. PKI for Signing: Use PKI to sign tokens, ensuring integrity and non-repudiation.
  4. Short-Lived Tokens: Rotate tokens frequently to mitigate exposure risks.

Key Takeaways

  • OAuth2 handles authorization, while OIDC adds identity verification for federated access.
  • Federated access reduces re-authentication friction while maintaining Zero Trust principles.
  • Keycloak and HashiCorp Vault enable secure token issuance and secret management.
  • Always validate tokens using PKI and enforce strict scope controls to prevent privilege escalation.
  • Use OIDC discovery endpoints to dynamically retrieve IdP metadata for interoperability.