Glossary · Protocols and standards
OpenID Connect (OIDC)
An identity layer on OAuth 2.0: the OpenID Provider issues a signed ID token, a JWT, that tells a client who the user is and how they signed in.
OpenID Connect (OIDC) is an identity layer on top of OAuth 2.0 that lets a client verify who an end user is, based on authentication performed by an authorization server that OIDC calls the OpenID Provider.
ID token. The core addition is the ID token, a JSON Web Token that the provider signs. It must contain iss (the issuer), sub (a stable identifier for the user at that issuer), aud (the client it was issued to), exp and iat. It must also carry nonce when the client sent one in the authentication request. An OAuth access token tells a resource server what a client may do. An ID token tells the client who authenticated and at which provider. The current text of the core specification is OpenID Connect Core 1.0 incorporating errata set 2, dated 15 December 2023.
Discovery. A provider that supports OpenID Connect Discovery publishes a JSON metadata document at its issuer URL plus /.well-known/openid-configuration. The document lists the provider’s endpoints, supported scopes and algorithms, and the jwks_uri where its signing keys are published.
In A2A. An Agent Card declares OIDC with an openIdConnectSecurityScheme whose required openIdConnectUrl is that discovery document. The specification’s sample card:
{
"securitySchemes": {
"google": {
"openIdConnectSecurityScheme": {
"openIdConnectUrl": "https://accounts.google.com/.well-known/openid-configuration"
}
}
},
"securityRequirements": [{"schemes": {"google": {"list": ["openid", "profile", "email"]}}}]
}
The client runs the OIDC flow out of band, then sends the resulting token with each request. The same scheme can protect an extended Agent Card that shows more detail to authenticated clients.
Limits for agents. An ID token identifies a user to one client. It does not, by itself, say that a separate agent may act for that user, or within what limits. That question belongs to delegation and mandates.
Neighbouring terms. OAuth 2.0 issues the access tokens. A JWKS publishes the keys that verify ID token signatures.