Use an OpenID Connect provider as the authority for user sign-in, and let applications validate signed tokens or use a backend session derived from that sign-in. Keep authentication centralized, but enforce authorization at every service that owns protected data.
Last updated: October 6, 2026.
Browser
-> SaaS frontend
-> OpenID Provider (authorization code + PKCE)
<- one-time authorization code
-> SaaS backend exchanges the code
<- ID token + access token
-> service validates issuer, audience, signature, expiry
-> service loads current tenant roles and permissionsOpenID Connect answers who authenticated; OAuth access tokens authorize calls to protected APIs. Do not treat an ID token as an API access token. Validate the issuer, audience, signature, expiry, and the transaction-specific state or nonce required by the chosen flow.
Prefer a standard flow over a custom login gateway
For browser sign-in, use the authorization code flow with PKCE through a maintained identity library or managed provider. The OAuth Security Best Current Practice recommends PKCE for confidential clients and requires it for public clients. OpenID Connect adds the signed ID token and standardized identity claims.
A reverse proxy can initiate login and maintain a secure browser session, but downstream services still need a trustworthy identity context. Forward signed, audience-restricted tokens or use a controlled backend-for-frontend pattern; do not trust arbitrary identity headers from the public network.
Make permission changes take effect quickly
Long-lived assertions should not be the sole source of current permissions. Keep access tokens short-lived, evaluate tenant membership and sensitive roles from an authoritative store, and provide a revocation path for disabled or compromised accounts. Cache authorization data briefly and invalidate it when administrators change access. Use separate service credentials for machine-to-machine calls, restrict each audience and scope, and rotate those credentials without depending on a user session.
The OpenID Connect Core specification defines authentication and ID-token validation. For application design, continue with roles and permissions, tenant isolation in SQL, and tenant-aware rate limiting.