Federation shifts where trust lives
Federation means another organisation's identity provider decides who gets into your systems.
That is efficient and it moves a critical dependency outside your control. Their compromise becomes your compromise, their session policies become yours, and their offboarding process determines whether their former employees can still reach you. Worth knowing before it is the thing that failed.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Redirect URI validation protects token deliveryPosted only where it fits
- Token audience prevents universal reuseA ticket for this gate only
