Start with Identity
Learning

Learn Identity by Ear: Podcast Episodes on OAuth, OIDC, SAML and Passkeys

A listening plan for people new to identity: 14 podcast episodes, in order, that teach OAuth, OpenID Connect, SAML and passkeys from the people who wrote the specs, with what each one covers and what to read alongside.

By SWI Community TeamUpdated 2026-10-018 min read
Key takeaways
  • Learn the protocols in this order: OAuth 2.0 (delegated authorization), then OpenID Connect (sign-in built on OAuth), then SAML (the older enterprise federation standard), then passkeys (phishing-resistant authentication).
  • Nine of the 14 episodes feature a specification author or standards-body leader, including Aaron Parecki, Justin Richer, Mike Jones, John Bradley, and the FIDO Alliance's Andrew Shikiar.
  • Listen with the matching spec explainer open: audio is good for the why and the history, but the flows and parameters stick better on the page.
  • Total listening time is about 12 hours, roughly two weeks of commutes.

If you are new to identity, the four protocols worth learning first are OAuth 2.0, OpenID Connect, SAML 2.0, and passkeys. The 14 podcast episodes below teach them in that order, and nine of them feature someone who wrote or now leads the relevant specification. Listen in sequence, keep the linked explainer open, and in about 12 hours of audio you will understand why each protocol exists, how the pieces fit, and where the common mistakes are.

How to use this list

Audio is good at the why: the problem a protocol solved, the history, the trade-offs its designers argued about. It is bad at exact flows and parameter names. So treat each episode as the lecture and the linked Start with Identity page as the textbook. Listen first, then skim the page while the conversation is fresh.

Each entry gives the show, the length where published, and one line on what it teaches. Most of those lines were checked against the episode's transcript; the full lists on our learning paths show which.

Part 1: OAuth 2.0, the foundation

OAuth is how an app gets permission to call an API on a user's behalf without seeing their password. Almost everything else in modern identity builds on it.

1. Open Authorization In The World Of AI With Aaron Parecki (The Secure Developer, 36 min, 2025). Parecki, an editor of OAuth 2.1, explains why OAuth was created for delegated access, how it evolved from 1.0 to 2.1, and how OpenID Connect and DPoP extend it. The second half covers authorizing AI agents and MCP servers, which shows why OAuth still matters for new problems. Start here.

2. SE Radio 376: Justin Richer On API Security with OAuth 2 (Software Engineering Radio, 74 min). Richer, co-author of OAuth 2 in Action, walks through the technical parts: token types, PKCE, JWTs, client secrets, and the right patterns for single-page and mobile apps. Older, but the fundamentals have not changed.

3. OAuth, "It's complicated." (The Changelog #456, 70 min). Parecki again, aimed at working developers: where OAuth gets complicated, how PKCE and the browser-based app guidance fix the common mistakes, and what OAuth 2.1 and GNAP change. Listen after the first two, when the vocabulary is familiar.

Read alongside: OAuth 2.0, OAuth 2.1, and our OAuth and OpenID Connect implementation guide.

Part 2: OpenID Connect, sign-in on top of OAuth

OAuth answers "may this app call the API?" OpenID Connect adds "who is this user?" by issuing an ID token, which is what makes "Sign in with" buttons work.

4. OpenID Connect with Mike Jones (Identity, Unlocked, 43 min). Mike Jones, one of the OpenID Connect specification editors, on its design and history: why it was built on OAuth, what developers got wrong early, and the legal work that made it freely implementable. This show's original feed is broken, so the link goes to Spotify, which still plays it.

Read alongside: OpenID Connect and OAuth vs OIDC.

Part 3: SAML, the enterprise federation standard

SAML predates OpenID Connect and still runs most workforce single sign-on. You will meet it the first time you connect a company's identity provider to a SaaS app.

5. #37 Access Management with Andy (Identity at the Center, 36 min). An entry-level tour of access management from an Okta guest: why OIDC and SAML both exist, and how scopes and protocol flows fit into single sign-on. The best plain-language bridge from OAuth to SAML.

6. SAML with Joni Brennan, Paul Madsen and Prateek Mishra (Identity, Unlocked, 42 min). Three people from SAML's standards community explain how the protocol works, who created it and why, and how OpenID Connect became the place where federation work moved on. Rare first-hand history.

7. Getting Rid of ADFS (Hybrid Identity Protection Podcast, 29 min). Microsoft MVP Sander Berkouwer on why organizations are retiring AD FS, the on-premises SAML federation server, and the practical steps to move that SSO to Entra ID. This is the SAML project most new identity engineers end up on.

Read alongside: SAML 2.0, SAML vs OIDC, and our AD FS to Entra migration playbook.

Part 4: Passkeys, sign-in without phishable secrets

Passkeys replace passwords with a key pair bound to the website, which is why they resist phishing. They are built on the FIDO2 and WebAuthn standards.

8. #56 What is FIDO with Andrew Shikiar (Identity at the Center, 47 min). Andrew Shikiar, who leads the FIDO Alliance, on what the Alliance is and which authentication problems its standards solve.

9. Passkeys vs. 2FA (Security Now 965). Steve Gibson answers the most common beginner worry: whether giving up a password plus second factor for a passkey is a downgrade. It is not, and the episode explains why.

10. WebAuthn and FIDO2 with John Bradley (Identity, Unlocked, 26 min). John Bradley, a FIDO2 specification author, on how WebAuthn and FIDO2 actually work.

11. FIDO Multi Device Credentials with Andrew Shikiar and Tim Cappalli (Identity, Unlocked, 41 min). Recorded in 2022, when "multi-device FIDO credentials" were about to be renamed passkeys: what they are and why synced credentials were introduced for consumers.

12. How General Motors Moved 200,000 People to Passkeys (Entra.Chat, 44 min, 2026). The rollout story: office, factory, call center, and guest users moved to passkeys without locking people out. Theory meets a real workforce.

13. #373 Going Passkey Phishing with Nishant Kaushik (Identity at the Center, 58 min). The FIDO Alliance CTO takes on common doubts about passkey security and adoption.

Read alongside: Passkeys 101, WebAuthn and FIDO2, and the passkey rollout checklist.

Bonus: where the protocols meet

14. SE Radio 526: Brian Campbell on Proof of Possession Defenses (Software Engineering Radio, 54 min). Once the basics land, this is the natural next step: how mutual TLS and DPoP bind OAuth tokens to the client so a stolen token is useless. Brian Campbell of Ping Identity co-authored both specifications.

Where to go next

Each protocol has a longer, ordered path that runs from basics to standards-group depth: OAuth and OpenID Connect (12 episodes), SAML and enterprise federation (10), and passkeys and FIDO (14). For a show to subscribe to rather than single episodes, Identity at the Center covers the whole field weekly, and A Digital Identity Digest explains standards in 12-minute episodes. Our Start here page lays out the reading path that goes with this listening plan.

Frequently asked questions

What is the best podcast to learn OAuth?
Start with The Secure Developer's episode with Aaron Parecki, an editor of OAuth 2.1, which explains why OAuth exists and how it evolved. Follow it with Software Engineering Radio episode 376 with Justin Richer for the technical pieces: tokens, PKCE, and app patterns. Both feature people who work on the specifications.
Can you learn OAuth from a podcast?
You can learn why OAuth exists, how its parts fit together, and which mistakes to avoid. Audio is weaker for exact flows and parameters, so pair each episode with a written explainer such as the Start with Identity OAuth 2.0 and OpenID Connect pages.
What is the difference between OAuth and OpenID Connect?
OAuth 2.0 is a framework for delegated authorization: it lets an app get a token to call an API on a user's behalf. OpenID Connect is an identity layer on top of OAuth that adds an ID token, so the app also learns who the user is and can sign them in.
Is SAML still worth learning?
Yes, if you work on workforce identity. Most enterprise single sign-on still runs on SAML 2.0, and migrations away from AD FS and similar federation servers are common projects. New consumer and API work uses OpenID Connect instead.
Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent editorial review, no sponsorship. See more in our articles and rankings.