Identity, Unlocked
The late Vittorio Bertocci's interviews with the authors of OAuth, OpenID Connect, FIDO, and SAML. Ended in 2022, and still the best audio archive on identity specs.
- Publisher
- Auth0 (now part of Okta) · Vendor
- Pillar
- Access, Authorization & Network, Workforce Identity
- Level
- Architect
- Format
- Interview
- Cadence
- Ended September 2022, 20 to 45 min
- Status
- Ended, last episode 2022-09-29
- Since
- 2020
- Episodes
- 26
What it is
Identity, Unlocked was hosted by Vittorio Bertocci, Principal Architect at Auth0, and produced in partnership with the OpenID Foundation and IDPro. Across 26 episodes in four seasons, from August 2020 to September 2022, he interviewed the people who wrote the specifications: Mike Jones on OpenID Connect, John Bradley on WebAuthn, Aaron Parecki on OAuth 2.1, Daniel Fett on the OAuth security best current practice and SD-JWT, and a SAML history episode with Joni Brennan, Paul Madsen, and Prateek Mishra.
Who it suits
Engineers and architects who want to understand why the standards are shaped the way they are, from the authors.
Editor note
Bertocci died in October 2023, and the show is complete. It remains the best audio archive on identity specifications, and its episodes anchor several of our learning paths, including OAuth and OpenID Connect and SAML. Warning: the original show website and feed now redirect to unrelated sites, and so does the audio Apple Podcasts plays, because it ran through the defunct Chartable tracking service. Spotify still serves its own copy; the episode links here go there. Some older episodes we could not locate on Spotify are left off our paths for now.
Where to start
- SAML with Joni Brennan, Paul Madsen and Prateek Mishra2022-08-31 · 42 min · Learner · SAML and enterprise federation
How the SAML protocol works, who built it and why, and how OpenID Connect later took over as the place where federation innovation happens.
- OpenID Connect with Mike Jones2021-12-20 · 43 min · Practitioner · OAuth and OpenID Connect
The design and history of OpenID Connect from one of its specification editors, covering protocol design, developer concerns, and legal aspects.
- System for Cross Domain Identity Management (SCIM) with Phil Hunt & Pamela Dingle2021-10-11 · 43 min · Practitioner · Identity governance (IGA)
What SCIM is and how it standardizes user provisioning between systems, explained by the editor of the SCIM specifications.
Also in our learning paths
- Daniel Fett on privacy-preserving measures and SD-JWT2022-09-29 · 47 min · Architect · Verifiable credentials and digital wallets
Surveys privacy-preserving techniques such as selective disclosure and zero-knowledge proofs, and explains how SD-JWT adds selective disclosure to JSON Web Tokens.
- FIDO Multi Device Credentials with Andrew Shikiar and Tim Cappalli2022-06-14 · 41 min · Practitioner · Passkeys and FIDO
What FIDO multi-device credentials, now called passkeys, are and why they were introduced as a password alternative for consumer applications.
- The Mobile Driving License Spec with Andrew Hughes2022-01-10 · 34 min · Architect · Verifiable credentials and digital wallets
Explains the ISO mobile driving license standard (ISO/IEC 18013-5), how mDL data and presentation work, and why it matters for daily life.
- WebAuthn and FIDO2 with John Bradley2020-11-09 · 26 min · Practitioner · Passkeys and FIDO
How WebAuthn and FIDO2 work, from one of the authors of the FIDO2 specifications.
Last verified 2026-09-30 against the show's feed, recent episode notes, and the publisher's own pages. Status and last-episode date update weekly from the feed.
Identity, Unlocked is produced by Auth0 (now part of Okta). Listed on the same terms as independent shows.
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].
Related on Start with Identity
- PodcastA Digital Identity Digest
Short weekly episodes from standards veteran Heather Flanagan that "translate geek to human" on identity standards, wallets, and the web platform.
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- GlossaryAccess Token
A short-lived credential a client presents to a resource server to access protected data. Access tokens are typically opaque or JWT-formatted, with lifetimes me
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- GlossaryAgentic Identity
Identity for autonomous AI agents that act on a user's behalf, call APIs, and chain tools. Requires scoped, delegated, auditable, and revocable credentials rath
- GlossaryAuthorization Code Flow
The recommended OAuth 2.0 flow for apps with a user: the app receives a short-lived code, then exchanges it for tokens from a back channel. Combined with PKCE f