Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Literally all of those enterprise SSO systems support OIDC. ADFS, PING, OKTA, Azure AD, ETC...


SAML has two way authentication and some advanced security stuff. The IDP and the SP must be registered to one another and can actively sign and verify their transactions. It is noteworthy for some use cases like AWS or bank authentication.

Nonetheless, we can all agree that SAML is an order of magnitude more difficult for no significant benefit. OpenID connect should be largely preferred.


You can verify transactions in openid as well


openid is a dead protocol that stopped being supported by major websites and authentication solutions years ago. Not to be confused with openid connect.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: