Start with Identity
Podcast learning path

OAuth and OpenID Connect, by ear

15 episodes, in order. Delegated authorization and federated sign-in, from first principles to the current security best practice. Start at the top if the topic is new to you, or jump to the stage that matches where you are.

Start here: the basics

  1. 1
    Open Authorization In The World Of AI With Aaron Parecki
    The Secure Developer · 2025-06-10 · 36 min · Learner

    Why OAuth was created for delegated access, how it evolved from 1.0 to 2.1, and how OpenID Connect and DPoP extend it.

  2. 2
    OAuth 2.0 from Protecting APIs to Supporting Authorization & Authentication - Aaron Parecki - ASW #289
    Application Security Weekly · 2024-06-25 · 61 min · Learner

    Why OAuth 2.0 is a family of specifications rather than one spec, and why it can be hard to secure by default and to make interoperable.

  3. 3
    SE Radio 376: Justin Richer On API Security with OAuth 2
    Software Engineering Radio · 2019-08-13 · 74 min · Learner

    The core technical features of OAuth 2.0, including token types, OpenID Connect, PKCE, JWTs, client secrets, and patterns for single-page and mobile apps.

In practice: rollouts and operations

  1. 4
    OAuth, "It's complicated." (Changelog Interviews #456)
    The Changelog · 2021-08-23 · 70 min · Practitioner

    Where OAuth 2.0 gets complicated, how PKCE and browser-based app guidance address it, and what OAuth 2.1 and GNAP change.

  2. 5
    OpenID Connect with Mike Jones
    Identity, Unlocked · 2021-12-20 · 43 min · Practitioner

    The design and history of OpenID Connect from one of its specification editors, covering protocol design, developer concerns, and legal aspects.

  3. 6
    What's new with OAuth2.1 with Aaron Parecki
    Identity, Unlocked · 2020-09-27 · 38 min · Practitioner

    What the OAuth 2.1 specification consolidates and changes compared with OAuth 2.0, explained by one of its editors.

  4. 7
    #237 - OAuth 2.0 Step Up Authentication Challenge Protocol with Vittorio Bertocci
    Identity at the Center · 2023-10-09 · 36 min · Practitioner

    What the OAuth 2.0 Step Up Authentication Challenge Protocol (RFC 9470) does, from its co-author.

Going deeper: standards, architecture, and attacks

  1. 8
    A Lap Around the OAuth2 Security BCP with Daniel Fett
    Identity, Unlocked · 2020-10-24 · 34 min · Architect

    What the OAuth 2.0 Security Best Current Practice document recommends, from a researcher who works on formal analysis of web protocols.

  2. 9
    SE Radio 526: Brian Campbell on Proof of Possession Defenses
    Software Engineering Radio · 2022-08-24 · 54 min · Architect

    How proof-of-possession defends against stolen OAuth tokens, comparing OAuth mTLS and DPoP and their security versus complexity trade-offs.

  3. 10
    PAR, RAR, and JAR with Filip Skokan
    Identity, Unlocked · 2021-02-08 · 21 min · Architect

    What Pushed Authorization Requests, Rich Authorization Requests, and JWT-Secured Authorization Requests add to OAuth authorization requests.

  4. 11
    Nat Sakimura delves into Financial-Grade API (FAPI)
    Let's Talk About Digital Identity · 2022-01-12 · Architect

    Why FAPI was created, its two core traits of integrity-protected messages and sender-constrained tokens, and where open banking uses it.

  5. 12
    #222 - Identity Standards with Justin Richer of Bespoke Engineering
    Identity at the Center · 2023-07-17 · 90 min · Architect

    How OpenID Connect might be designed differently today and what the Grant Negotiation and Authorization Protocol (GNAP) aims to change.

  6. 13
    Delegation in a Multi-Actor World: It's Not Just OAuth Anymore
    A Digital Identity Digest · 2025-06-27 · 12 min · Architect

    Where OAuth 2.0 falls short for multi-party delegation and what OAuth Token Exchange (RFC 8693) does and does not provide.

  7. 14
    #422 - Decoded - Securing AI Agents with Standards You Already Have
    Identity at the Center · 2026-05-15 · 78 min · Architect

    How existing OAuth specifications such as JWT authorization grant, token exchange, and client ID metadata, plus SPIFFE, apply to securing AI agents as workloads.

    Pieter Kasselman (Defakto)agentic identity
  8. 15
    #449 - Decoded - Transaction Tokens with George Fletcher
    Identity at the Center · 2026-09-21 · 71 min · Architect

    How OAuth Transaction Tokens secure requests across microservices, including their claims, time to live, immutability, and use with AI agents.

How this list was built

Episodes are chosen for what they teach, not for who published them, and ordered so each one builds on the last. Each note is written from the episode's published show notes and checked against the episode page. Vendor-produced shows are labelled on their directory profiles. Know a better episode for a step on this path? Email [email protected].

Last reviewed By SWI Community TeamSuggest a correctionHow we research