Skip to content
Tech Interview Prep home
Technical interview guide

SSO & Federation Protocols (SAML, OIDC)

How a user authenticates once with an identity provider and gets trusted access across many applications.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: OIDC Core 1.0, OAuth 2.0 with RFC 9700 BCP, SAML 2.0, SCIM 2.0, and NIST SP 800-63C-4 guidance current 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain OAuth, OIDC, SAML, SSO, and SCIM without conflating them.

QA-2

Design an OIDC authorization code flow with PKCE.

QA-3

Define safe ID-token and access-token handling.

QA-4

Implement robust OIDC ID-token validation.

QA-5

Compare state, nonce, and PKCE in an OIDC login.

QA-6

Harden OIDC redirects and post-login navigation.

QA-7

Review a PKCE implementation for downgrade and verifier risks.

QA-8

Secure a relying party that supports many OIDC providers.

QA-9

Design federated identity mapping and account linking.

QA-10

Map federated groups and claims to local authorization.

QA-11

Design joiner-mover-leaver lifecycle around federated SSO.

QA-12

Implement secure SAML Web Browser SSO validation.

QA-13

Design SAML replay and assertion-injection protection.

QA-14

Plan SAML and OIDC signing-key rotation.

QA-15

Harden OIDC discovery and JWKS caching.

QA-16

Prevent JWT algorithm and cross-token confusion.

QA-17

Design local and federated logout behavior.

QA-18

Implement step-up authentication for a sensitive operation.

QA-19

Design privacy-preserving federation attributes.

QA-20

Evaluate whether to support IdP-initiated SAML SSO.

QA-21

Handle email reuse, rename, and account collision in federation.

QA-22

Implement reliable SCIM deactivation and reconciliation.

QA-23

Design federation observability and audit logging.

QA-24

Build an adversarial federation test matrix.

QA-25

Respond to an IdP signing-key or federation metadata compromise.