OAuth2 & OpenID Connect Deep Dive · Lektion

Single Sign-On über mehrere Anwendungen

Lernen Sie, wie OAuth2 und OpenID Connect Single Sign-On ermöglichen, sodass sich Benutzer einmal authentifizieren und nahtlos auf mehrere Anwendungen zugreifen können.

Lektion 4 von 413 Schritte

Single Sign-On über mehrere Anwendungen ist eine kostenlose OAuth2 & OpenID Connect Deep Dive-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des OAuth2 & OpenID Connect Deep Dive-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

What Is SSO?

Single Sign-On lets a user authenticate once with a central identity provider and then access many applications without logging in again. OpenID Connect is the modern foundation for web and mobile SSO.

The Central Session

The magic lives at the OpenID Provider (OP). When the user logs in, the OP establishes its own session (often a cookie). Each app relies on that central session rather than maintaining its own credentials.

First App Login

App A redirects the user to the OP's /authorize endpoint. The user enters credentials, the OP sets its session cookie, and returns an authorization code to App A, which exchanges it for tokens.

Second App: Silent Login

Later the user opens App B, which also redirects to /authorize. Because the OP session cookie already exists, the OP recognizes the user and returns a code without prompting for credentials again. That is the SSO experience.

prompt=none

To check silently whether a session exists, apps can use prompt=none. The OP either returns a code immediately or an error like login_required if no session is present.

GET /authorize?response_type=code
  &client_id=appB&scope=openid
  &redirect_uri=https://b.example.com/cb
  &prompt=none

Forcing Re-authentication

Conversely, sensitive operations can require a fresh login with prompt=login or a max_age constraint, overriding the SSO session for that request.

Identity Provider Federation

The OP itself may federate to upstream providers (corporate IdP, Google, social logins). To the apps it still looks like one OP, but the OP brokers authentication to the chosen source. This centralizes policy and simplifies clients.

Single Logout

SSO needs Single Logout too: when the user signs out of one app, related sessions should end. OIDC offers front-channel and back-channel logout to notify participating apps and clear the central session.

Session Token Lifetimes

Balance convenience and security: short access tokens with refresh tokens for ongoing access, and an OP session lifetime that matches your risk tolerance. Long SSO sessions are convenient but widen the impact of a compromised device.

Native and Mobile SSO

On mobile, SSO uses the system browser (ASWebAuthenticationSession / Custom Tabs) so the OP cookie is shared across apps. Embedded WebViews break SSO and are discouraged for security and usability reasons.

Benefits and Risks

SSO improves UX, centralizes MFA and auditing, and reduces password fatigue. The trade-off: the OP becomes a high-value target, so it must be hardened, monitored, and protected with strong authentication.

Quick Check

Test your SSO understanding.

Recap

Single Sign-On centralizes authentication at the OpenID Provider.

  • The OP session lets subsequent apps log in silently.
  • prompt=none checks for a session; prompt=login/max_age force re-auth.
  • Single Logout coordinates ending sessions across apps.
  • Use the system browser, not embedded WebViews, for mobile SSO.
Kostenlos starten

Lerne OAuth2 & OpenID Connect Deep Dive mit einem KI-Tutor — kostenlos

Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.

Kurse
12
Lektionen
48

Häufig gestellte Fragen

Ist die Lektion „Single Sign-On über mehrere Anwendungen“ kostenlos?

Ja — der vollständige Text von „Single Sign-On über mehrere Anwendungen“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des OAuth2 & OpenID Connect Deep Dive-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Single Sign-On über mehrere Anwendungen“?

Lernen Sie, wie OAuth2 und OpenID Connect Single Sign-On ermöglichen, sodass sich Benutzer einmal authentifizieren und nahtlos auf mehrere Anwendungen zugreifen können. Du übst OAuth2 & OpenID Connect Deep Dive mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um OAuth2 & OpenID Connect Deep Dive zu starten?

Keine Vorkenntnisse erforderlich. OAuth2 & OpenID Connect Deep Dive auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.

Wie lange dauert die Lektion „Single Sign-On über mehrere Anwendungen“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser OAuth2 & OpenID Connect Deep Dive-Lektion Code schreiben und ausführen?

Ja. Jede OAuth2 & OpenID Connect Deep Dive-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Integration mit Identity Providern
  2. Microservices- und API-Gateway-Sicherheit
  3. Multi-Faktor-Authentifizierung (MFA)
  4. Single Sign-On über mehrere Anwendungen
← Zurück zu OAuth2 & OpenID Connect Deep Dive