✳ Learning path / 3 lessons
Trust tickets, not hallway trust
Three lessons on OAuth tickets, OIDC and SAML sign-in claims, and five federation failure habits. Builds on F4. Practices trust decisions. Does not replace the glossary term guides.
Work through the lessons in sequence, or choose the question you want to answer today.
01Who holds the ticket, and what does it open?
Map the four OAuth roles, tell an access ticket from a sign-in, and treat scope and audience as privilege limits.
ID Token and SAML assertion are claims, not blank admin passes
Read an OIDC ID Token and a SAML assertion as sign-in claims, then list the checks the relying party still owns.
Five ways the ticket still burns you
Map five federation failure concepts to owner habits: token theft, confused deputy, mis-audience, IdP compromise, and assertion replay.
Turn knowledge into a decision.
Once you have the ideas, try a short scenario. You’ll see why the tempting answer isn’t always the most useful one.
Open the practice range ↗