OpenID Connect is a layer on top of OAuth 2.0 that lets websites verify who you are

OpenID Connect is a standard that websites use to confirm your identity when you log in. It sits on top of OAuth 2.0, which is the system that lets you give a website permission to access your data from another service. OpenID Connect adds identity verification to that permission system — so a website doesn't just know you gave permission, it knows who you actually are.

When you click "Sign in with Google" or "Sign in with Facebook" on a website, you're usually using OpenID Connect. The website sends you to Google or Facebook, you log in there, and then Google or Facebook tells the website "Yes, this is James Rodriguez" and sends back information about you. The website then creates an account or logs you in based on that confirmation.

The key difference from plain OAuth 2.0 is that OpenID Connect includes an ID token — a digital package of information about who you are. OAuth 2.0 only handles permission to access data; OpenID Connect handles both permission and identity.

Key Takeaways

  • OpenID Connect verifies your identity through a trusted service like Google or Facebook, so websites don't have to store your password.
  • It combines OAuth 2.0 (permission to access data) with an ID token (proof of who you are).
  • When you use "Sign in with" buttons on websites, you are almost always using OpenID Connect.
  • The website you're logging into never sees your password — the identity provider (Google, Facebook, etc.) handles the verification.

How the login flow actually works

When you click "Sign in with Google" on a website, several things happen in order. First, the website redirects you to Google's login page. You enter your email and password there — not on the website you're trying to access. Google verifies your password and asks if you want to let this website see your profile information.

Once you agree, Google creates an ID token and sends you back to the website along with that token. The website reads the ID token to learn your name, email address, and other details Google included. The website then either creates a new account for you or logs you into an existing one using that information.

Throughout this process, the website never sees your Google password. Google is the only service that knows your actual password. The website only receives a signed confirmation from Google that says "This person is James Rodriguez, and I verified them."

The difference between OpenID Connect and OAuth 2.0

OAuth 2.0 is purely about permission. It lets you tell a service "You can read my photos from Google Photos" or "You can post to my Twitter account." The service gets an access token that proves you gave permission, but OAuth 2.0 doesn't tell the service who you are — it only proves you authorized something.

OpenID Connect adds identity on top of that. It includes an ID token that contains claims about who you are — your name, email, profile picture, and other details the identity provider knows about you. The website can read this token and know not just that someone gave permission, but specifically who that someone is.

Many services use both. When you sign in with Google, OpenID Connect handles the identity part (proving you are you). If the website also wants permission to read your Google Calendar or send emails on your behalf, that's OAuth 2.0 handling the permission part.

Why websites use OpenID Connect instead of passwords

Websites that use OpenID Connect don't have to store your password. That's safer for you because if that website gets hacked, hackers don't get your password — they only get information the website already displayed publicly, like your name and email. Your actual password stays with Google, Facebook, or whichever service you used to sign in.

It's also safer for the website. They don't have to build and maintain a password database, which is a common target for hackers. They can rely on Google or Facebook, which have security teams dedicated to protecting passwords.

For you as a user, it means fewer passwords to remember. You can use the same Google account to sign into dozens of websites. If you change your password at Google, it automatically takes effect everywhere you use that account to sign in.

What information OpenID Connect shares with websites

The ID token contains claims — pieces of information about you. The standard claims include your unique ID at that identity provider, your email address, whether your email is verified, your name, and your profile picture URL. Websites can request additional claims, like your phone number or address, but you have to approve sharing those.

You control what gets shared. When you click "Sign in with Google," Google shows you a screen listing what information the website wants. You can see exactly what the website will receive before you approve it. If a website asks for your phone number and you don't want to share it, you can deny that request — though the website might then refuse to let you sign in.

The identity provider (Google, Facebook, etc.) keeps a record of which websites you've signed into and what information you shared with each one. You can usually review and revoke this access from your account settings at the identity provider.

Common identity providers that use OpenID Connect

Google is the most common. Most websites that offer "Sign in with Google" are using OpenID Connect. Facebook offers the same through "Sign in with Facebook." Microsoft, Apple, GitHub, and LinkedIn all support OpenID Connect as well.

Some organizations run their own OpenID Connect servers for internal use. A company might set up OpenID Connect so employees can use their work email to sign into internal tools without creating separate passwords for each tool.

The standard is open, meaning any organization can build an identity provider that follows the OpenID Connect rules. This is why you see it used consistently across different websites — they're all following the same standard for how identity verification works.

Security considerations when using OpenID Connect

OpenID Connect is generally secure because the identity provider handles password verification, not the website you're signing into. However, security still depends on the identity provider you choose. If you use Google, your security is as strong as Google's security. If you use a smaller service, it depends on how seriously that service takes security.

One risk is that if someone gains access to your Google account, they can sign into any website you've connected to Google. This is why using a strong, unique password for your Google account (or enabling two-factor authentication) matters more than ever.

Websites that use OpenID Connect should validate the ID token properly — checking that it actually came from the identity provider and hasn't been tampered with. Most libraries that implement OpenID Connect do this automatically, but poorly built websites might skip this step.

Frequently Asked Questions

Is OpenID Connect the same as single sign-on?

OpenID Connect is one way to build single sign-on, but they're not the same thing. Single sign-on means you log in once and gain access to multiple systems. OpenID Connect is a standard way to implement that. A company could use OpenID Connect, SAML, or other standards to build single sign-on.

Can I use OpenID Connect if I don't have a Google or Facebook account?

That depends on the website. Some websites only offer "Sign in with Google" and nothing else — in that case, you'd need a Google account. Other websites offer multiple options like Google, Facebook, and email/password. If a website supports email and password login, you can use that instead of OpenID Connect.

What happens to my account if I delete my Google account?

If you delete your Google account, you won't be able to sign into websites using "Sign in with Google" anymore. Websites that use OpenID Connect typically don't delete your account on their service when you delete your identity provider account — you just lose the ability to sign in that way. You'd need to contact the website to regain access or set up a different sign-in method.

Does OpenID Connect work on mobile apps?

Yes. Mobile apps can use OpenID Connect the same way websites do. When you tap "Sign in with Google" in an app, it opens your browser, you log in at Google, and then the app receives the ID token. Some apps use a slightly different flow that doesn't open a browser, but the result is the same.

Can websites see my password if I use OpenID Connect?

No. Your password stays with the identity provider (Google, Facebook, etc.). The website you're signing into never sees your password. It only receives a signed confirmation that the identity provider verified you.