← back to projects

OAuth2 Authentication Service

2021

One OAuth2.0 / OpenID Connect service replacing per-product logins across multi-tenant fintech apps.

Results

What it did

OAuth2.0OIDC Standard
1→manyReused Across Products
RS256Signed JWT Tokens
SSOCentralized Identity

The problem

Why it needed building

Multiple fintech applications each needed secure authentication and authorization, but per-app identity is duplicated, inconsistent, and hard to audit under financial regulation. They needed one trustworthy security backbone every product could rely on — with single sign-on, consistent token handling, and a single auditable place for access policy.

The approach

How it works

Built an OAuth2.0 / OIDC service on IdentityServer issuing signed RS256 JWT access tokens with fine-grained scopes. Each resource API independently validates signature, issuer, audience, scope, and expiry, so trust never depends on a shared session store. Centralizing identity gave every product single sign-on and one place to reason about access.

  1. Authorization Request
  2. Authenticate & Consent
  3. Token Issuance
  4. Token Validation
  5. Centralized Identity
  1. 01
    Authorization RequestClient redirects to IdentityServer with client_id and requested scopes
  2. 02
    Authenticate & ConsentUser credentials verified and scope consent captured
  3. 03
    Token IssuanceSigned RS256 JWT issued with scopes, audience, and expiry
  4. 04
    Token ValidationResource APIs verify signature, issuer, audience, and scope independently
  5. 05
    Centralized IdentityOne auth service reused as the security backbone across products

Live demo

Try it yourself

Client AppAuthorization RequestGET /connect/authorize?client_id=payments-web&scope=openid+payments.read
IdentityServerAuthenticate & ConsentUser signed in · consent granted for requested scopes
IdentityServerToken IssuedPOST /connect/token → 200 OK · access_token (JWT, signed RS256)
Resource APIValidate TokenVerify RS256 signature · issuer · audience · scope · expiry
Resource APIAccess Granted200 OK · scope payments.read satisfied
Decoded access_token
{
  "alg": "RS256",
  "typ": "JWT",
  "kid": "a1b2c3d4"
}
{
  "sub": "user_8842",
  "client_id": "payments-web",
  "scope": "openid payments.read",
  "iss": "https://id.example.sa",
  "exp": 1717603200
}

Illustrative of the OAuth2.0 / OIDC service — a representative flow, not a live endpoint.

Tech stack

Built with

.NET CoreIdentityServerOAuth2OIDCJWTRS256SQL Server

Working on something like this?