# Learn Identity by Ear: Podcast Episodes on OAuth, OIDC, SAML and Passkeys

Source: https://startwithidentity.com/articles/learn-identity-podcasts-oauth-oidc-saml-passkeys/
Last updated: 2026-10-01
License: content by Start with Identity. Cite the source URL.

---

If you are new to identity, the four protocols worth learning first are [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/), [OpenID Connect](https://startwithidentity.com/standards/openid-connect/), [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/), and [passkeys](https://startwithidentity.com/glossary/passkey/). The 14 podcast episodes below teach them in that order, and nine of them feature someone who wrote or now leads the relevant specification. Listen in sequence, keep the linked explainer open, and in about 12 hours of audio you will understand why each protocol exists, how the pieces fit, and where the common mistakes are.

## How to use this list

Audio is good at the why: the problem a protocol solved, the history, the trade-offs its designers argued about. It is bad at exact flows and parameter names. So treat each episode as the lecture and the linked Start with Identity page as the textbook. Listen first, then skim the page while the conversation is fresh.

Each entry gives the show, the length where published, and one line on what it teaches. Most of those lines were checked against the episode's transcript; the full lists on our [learning paths](https://startwithidentity.com/podcasts/learn/) show which.

## Part 1: OAuth 2.0, the foundation

OAuth is how an app gets permission to call an API on a user's behalf without seeing their password. Almost everything else in modern identity builds on it.

**1. [Open Authorization In The World Of AI With Aaron Parecki](https://snyk.io/podcasts/the-secure-developer/open-authorization-in-the-world-of-ai-with-aaron-parecki/)** (The Secure Developer, 36 min, 2025). Parecki, an editor of OAuth 2.1, explains why OAuth was created for delegated access, how it evolved from 1.0 to 2.1, and how OpenID Connect and DPoP extend it. The second half covers authorizing AI agents and MCP servers, which shows why OAuth still matters for new problems. Start here.

**2. [SE Radio 376: Justin Richer On API Security with OAuth 2](https://se-radio.net/2019/08/episode-376-justin-richer-on-api-security-with-oauth-2/)** (Software Engineering Radio, 74 min). Richer, co-author of *OAuth 2 in Action*, walks through the technical parts: token types, [PKCE](https://startwithidentity.com/glossary/pkce/), [JWTs](https://startwithidentity.com/glossary/jwt/), client secrets, and the right patterns for single-page and mobile apps. Older, but the fundamentals have not changed.

**3. [OAuth, "It's complicated."](https://changelog.com/podcast/456)** (The Changelog #456, 70 min). Parecki again, aimed at working developers: where OAuth gets complicated, how PKCE and the browser-based app guidance fix the common mistakes, and what [OAuth 2.1](https://startwithidentity.com/standards/oauth-2-1/) and GNAP change. Listen after the first two, when the vocabulary is familiar.

Read alongside: [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/), [OAuth 2.1](https://startwithidentity.com/standards/oauth-2-1/), and our [OAuth and OpenID Connect implementation guide](https://startwithidentity.com/guides/implementation/oauth-2-openid-connect-implementation/).

## Part 2: OpenID Connect, sign-in on top of OAuth

OAuth answers "may this app call the API?" OpenID Connect adds "who is this user?" by issuing an ID token, which is what makes "Sign in with" buttons work.

**4. [OpenID Connect with Mike Jones](https://open.spotify.com/episode/6OvmRvYYEAslOyWYKzM7EE)** (Identity, Unlocked, 43 min). [Mike Jones](https://startwithidentity.com/experts/mike-jones/), one of the OpenID Connect specification editors, on its design and history: why it was built on OAuth, what developers got wrong early, and the legal work that made it freely implementable. This show's original feed is broken, so the link goes to Spotify, which still plays it.

Read alongside: [OpenID Connect](https://startwithidentity.com/standards/openid-connect/) and [OAuth vs OIDC](https://startwithidentity.com/guides/fundamentals/oauth-vs-oidc/).

## Part 3: SAML, the enterprise federation standard

SAML predates OpenID Connect and still runs most workforce single sign-on. You will meet it the first time you connect a company's identity provider to a SaaS app.

**5. [#37 Access Management with Andy](https://creators.spotify.com/pod/profile/identity-at-the-center/episodes/37---Access-Management-with-Andy-ebnppr)** (Identity at the Center, 36 min). An entry-level tour of access management from an [Okta](https://startwithidentity.com/vendors/iam/okta/) guest: why OIDC and SAML both exist, and how scopes and protocol flows fit into [single sign-on](https://startwithidentity.com/guides/authentication/complete-guide-implementing-sso/). The best plain-language bridge from OAuth to SAML.

**6. [SAML with Joni Brennan, Paul Madsen and Prateek Mishra](https://open.spotify.com/episode/72Rjj6ua78CLMPZaymCbVw)** (Identity, Unlocked, 42 min). Three people from SAML's standards community explain how the protocol works, who created it and why, and how OpenID Connect became the place where federation work moved on. Rare first-hand history.

**7. [Getting Rid of ADFS](https://www.hipconf.com/podcast?wchannelid=nfpsk82o5v&wmediaid=jfpmcftzjb)** (Hybrid Identity Protection Podcast, 29 min). Microsoft MVP Sander Berkouwer on why organizations are retiring AD FS, the on-premises SAML federation server, and the practical steps to move that SSO to Entra ID. This is the SAML project most new identity engineers end up on.

Read alongside: [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/), [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/), and our [AD FS to Entra migration playbook](https://startwithidentity.com/guides/implementation/adfs-to-entra-migration/).

## Part 4: Passkeys, sign-in without phishable secrets

Passkeys replace passwords with a key pair bound to the website, which is why they resist phishing. They are built on the FIDO2 and WebAuthn standards.

**8. [#56 What is FIDO with Andrew Shikiar](https://podcasters.spotify.com/pod/show/identity-at-the-center/episodes/56---What-is-FIDO-with-Andrew-Shikiar-ehpq2a)** (Identity at the Center, 47 min). [Andrew Shikiar](https://startwithidentity.com/experts/andrew-shikiar/), who leads the FIDO Alliance, on what the Alliance is and which authentication problems its standards solve.

**9. [Passkeys vs. 2FA](https://twit.tv/shows/security-now/episodes/965)** (Security Now 965). Steve Gibson answers the most common beginner worry: whether giving up a password plus second factor for a passkey is a downgrade. It is not, and the episode explains why.

**10. [WebAuthn and FIDO2 with John Bradley](https://open.spotify.com/episode/2meHlatxlJje6dGQ3Zrxrf)** (Identity, Unlocked, 26 min). [John Bradley](https://startwithidentity.com/experts/john-bradley/), a FIDO2 specification author, on how [WebAuthn](https://startwithidentity.com/standards/webauthn-fido2/) and FIDO2 actually work.

**11. [FIDO Multi Device Credentials with Andrew Shikiar and Tim Cappalli](https://open.spotify.com/episode/0OLQFC1tSkwuqDBvTp7J1d)** (Identity, Unlocked, 41 min). Recorded in 2022, when "multi-device FIDO credentials" were about to be renamed passkeys: what they are and why synced credentials were introduced for consumers.

**12. [How General Motors Moved 200,000 People to Passkeys](https://entra.news/p/how-general-motors-moved-200000-people)** (Entra.Chat, 44 min, 2026). The rollout story: office, factory, call center, and guest users moved to passkeys without locking people out. Theory meets a real workforce.

**13. [#373 Going Passkey Phishing with Nishant Kaushik](https://podcasters.spotify.com/pod/show/identity-at-the-center/episodes/373---Going-Passkey-Phishing-with-Nishant-Kaushik-e37ppci)** (Identity at the Center, 58 min). The FIDO Alliance CTO takes on common doubts about passkey security and adoption.

Read alongside: [Passkeys 101](https://startwithidentity.com/guides/authentication/passkeys-101/), [WebAuthn and FIDO2](https://startwithidentity.com/standards/webauthn-fido2/), and the [passkey rollout checklist](https://startwithidentity.com/templates/passkey-rollout-checklist/).

## Bonus: where the protocols meet

**14. [SE Radio 526: Brian Campbell on Proof of Possession Defenses](https://se-radio.net/2022/08/episode-526-brian-campbell-on-proof-of-possession-defenses/)** (Software Engineering Radio, 54 min). Once the basics land, this is the natural next step: how mutual TLS and DPoP bind OAuth tokens to the client so a stolen token is useless. [Brian Campbell](https://startwithidentity.com/experts/brian-campbell/) of [Ping Identity](https://startwithidentity.com/vendors/iam/ping-identity/) co-authored both specifications.

## Where to go next

Each protocol has a longer, ordered path that runs from basics to standards-group depth: [OAuth and OpenID Connect](https://startwithidentity.com/podcasts/learn/oauth-oidc/) (12 episodes), [SAML and enterprise federation](https://startwithidentity.com/podcasts/learn/saml/) (10), and [passkeys and FIDO](https://startwithidentity.com/podcasts/learn/passkeys-fido/) (14). For a show to subscribe to rather than single episodes, [Identity at the Center](https://startwithidentity.com/podcasts/identity-at-the-center/) covers the whole field weekly, and [A Digital Identity Digest](https://startwithidentity.com/podcasts/a-digital-identity-digest/) explains standards in 12-minute episodes. Our [Start here](https://startwithidentity.com/start-here/) page lays out the reading path that goes with this listening plan.
