Open cardosec

Case E94A6B · Identity & AD · L1 Foundations

SAML vs OIDC

Practise as: Explain it · Interview

Interview questionWhen would you choose SAML over OpenID Connect for single sign-on?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Both let an identity provider assert who the user is to a service provider, enabling SSO
  2. SAML: XML assertions signed by the IdP, usually via browser POST; dominant in legacy enterprise apps
  3. OIDC: identity layer on OAuth 2.0 using signed JWT ID tokens; simpler for mobile, SPAs and APIs
  4. SAML risks: XML signature wrapping and weak signature validation; OIDC risks: skipping aud/iss/nonce checks
  5. Choose by ecosystem: SAML where enterprise apps require it, OIDC for modern and API-first apps

If the interviewer pushes back

  • What is XML signature wrapping and why does it keep appearing in SAML libraries?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.