OAuth2 Authentication Service
2021
One OAuth2.0 / OpenID Connect service replacing per-product logins across multi-tenant fintech apps.
Results
What it did
The problem
Why it needed building
Multiple fintech applications each needed secure authentication and authorization, but per-app identity is duplicated, inconsistent, and hard to audit under financial regulation. They needed one trustworthy security backbone every product could rely on — with single sign-on, consistent token handling, and a single auditable place for access policy.
The approach
How it works
Built an OAuth2.0 / OIDC service on IdentityServer issuing signed RS256 JWT access tokens with fine-grained scopes. Each resource API independently validates signature, issuer, audience, scope, and expiry, so trust never depends on a shared session store. Centralizing identity gave every product single sign-on and one place to reason about access.
- Authorization Request
- Authenticate & Consent
- Token Issuance
- Token Validation
- Centralized Identity
- 01Authorization RequestClient redirects to IdentityServer with client_id and requested scopes
- 02Authenticate & ConsentUser credentials verified and scope consent captured
- 03Token IssuanceSigned RS256 JWT issued with scopes, audience, and expiry
- 04Token ValidationResource APIs verify signature, issuer, audience, and scope independently
- 05Centralized IdentityOne auth service reused as the security backbone across products
Live demo
Try it yourself
{ "alg": "RS256", "typ": "JWT", "kid": "a1b2c3d4" } { "sub": "user_8842", "client_id": "payments-web", "scope": "openid payments.read", "iss": "https://id.example.sa", "exp": 1717603200 }
Illustrative of the OAuth2.0 / OIDC service — a representative flow, not a live endpoint.
Tech stack
Built with
Working on something like this?