SecurityBackend

SAML / OIDC

Also written as SAML, OIDC, OpenID Connect, Okta

The two standard protocols that make single sign-on work. SAML is the older XML-based standard, common in enterprise tools. OpenID Connect (OIDC), built on OAuth, is the modern default. Okta and Microsoft Entra ID (Azure AD) are the identity providers that speak them.

Think of it like

Two different passport formats that let you through many border gates after one identity check.

Junior or senior?

Setting up an app in Okta through its admin screens is a much lighter skill than implementing SAML or OIDC in your own product.

Senior sounds like

Has debugged a failing login by reading the actual assertion or token.

Ask them

“Have you implemented SSO in a product yourself, or configured it in an identity provider? What broke along the way?”

Sounds like real experience

Says clearly which side they were on (building the app or configuring the identity provider) and describes a specific failure, such as clock skew, a certificate expiring or mismatched claims.

Probe further if

Can only describe clicking 'Sign in with Okta' and can't say what the application actually checks.