OpenID Connect: In a Nutshell

profile picture Elly Heath 4 min read
A lady using a log-in page on a laptop

There is a lot of information available about OpenID Connect (OIDC). A quick search online and it’s easy to get lost in technical jargon and still be left clueless as to what it actually is and if it could be useful for your business. 

In this blog, we cut through the noise and break it down for you.

How did OpenID Connect come to be?

Less than a decade ago, businesses in the online retail, search and social media spaces required you to set up an account and your details were stored. 

This created two problems: you had to sign up on every website (and remember those credentials for the future), and in the online retail world, customers would often fill their baskets but not checkout due to the effort of having to create an account. Not to mention the administrative and security risks for businesses of storing customer information.

Enter OpenID Connect.

What is OpenID Connect?

Launched in 2014 by the OpenID Foundation, OIDC lets you use single sign-on (SSO) to access multiple sites using OpenID Providers. For example, logging in to Spotify using your Facebook account credentials. 

OIDC is the third generation of OpenID technology and is now the leading online interface to achieve multiple domain SSO and prove your identity. 

OIDC is web and mobile-friendly, as well as API friendly. If you’re interested in learning about the technical details, you can find more information about how it works here

Some of the biggest brands are providers of OIDC, including Google, Apple, Microsoft, Facebook, X and Spotify. Any company who needs to capture customer credentials online and is keen to reduce barriers for users, should consider if OIDC is right for their business.

Let’s take a closer look at the benefits to both users and businesses. 

Benefits of OpenID Connect

The main benefit for users is reduced time and effort in having to set up multiple accounts (and remember all those passwords!). You can visit the same website many times or navigate seamlessly across numerous websites without needing to sign in every time – particularly benefiting retail businesses with reduced barriers at the point of sale. 

There may also be a feeling of trust for some users when interacting with a business for the first time if they can use their pre-existing credentials. This benefits businesses as they can rely on the trust users have in third party well-established brands in the space. 

There are some drawbacks to OIDC to be aware of too.

Possible cons of OpenID Connect

To be effective, businesses are relying on users being willing to use OIDC in the first place. Users are increasingly aware of their online footprint and so may be wary of logging in with their social media credentials for example, thinking that they are sharing their entire profile. People are more cautious than ever before about businesses gaining access to their personal information and exploiting it.

The authorisation of OIDC could also come into question in some circumstances. For instance, when you log in with Google: 

  1. If you’re already logged in to Google in the same browser that you’re asked to “log in with Google” (on another website), you won’t be asked to enter your password again 
  2. If you aren’t already logged in to Google, the other website will you ask for your password to prove its you

 

With option 1, anyone with access to your laptop or mobile would be able to browse online via your credentials, without being asked for a password. 

 

And there you have it – OpenID Connect in a nutshell. If you have any other questions about OIDC, please get in touch.

Keep reading

A man placing his face in the frame to perform a facial age estimation with Yoti

How accurate is facial age estimation?

“How accurate is it?” is the first question regulators, businesses and users tend to ask about facial age estimation. To date, we have mainly presented the technology’s Mean Absolute Error (MAE) as a proxy for accuracy. It’s an intuitive way to understand how accurate a model is. We can say it’s accurate to 1.3 MAE for those aged between 13 and 17 years or 2.5 MAE for those aged between 6 and 70 years. However, the answer is slightly more complicated. Following the COVID-19 pandemic, many people will be more aware of the terms ‘true positive’ and ‘false negative’

5 min read
An image of man with an 'over 18' facial age estimation credential. Around him are icons representing the gambling, gaming, financial services and retail industries.

How Yoti’s facial age estimation is used across different industries

Checking users’ ages has never been more critical for businesses catering to diverse audiences. However, they’re faced with the challenge of effectively verifying the ages of their users whilst maintaining seamless and user-friendly experiences.  Yoti’s facial age estimation is a secure, privacy-preserving way to do just that. Our technology is used across a variety of industries, both online and in-person. This includes retail, social media, dating, gaming, gambling and financial services. In this blog, we explore how businesses are using facial age estimation to create safer, more positive experiences for their users.   What is facial age estimation? Facial

10 min read
Tiles of logos on a dark blue background including dropbox, gusto and google drive among others

Introducing integrations: making it easier for you to use Yoti

Today, we’re launching our integrations, helping businesses streamline identity and age verification processes and embed them within their existing software. So far, we have over 70 integrations. That’s more than any other identity company.    Yoti integrates into over 70 of the biggest SAAS products  From video conferencing platforms, HR platforms, customer relationship management (CRM) tools and financing and accounting software, you can benefit from our verification solutions without the expensive integration costs. We’ll build, monitor and manage the integrated systems you choose – there’s no need to allocate the time and resources of your team.  Streamlining verification processes within

3 min read