API authentication
User login and identity authentication can use OpenID Connect (OIDC); OAuth 2.0 is fundamentally an authorization framework, and delegated API access normally uses an OAuth 2.0 access token rather than treating OAuth itself as an authentication protocol. Service-to-service authentication can use mTLS, workload identity, or signed requests. APIs should validate authenticity and applicability according to credential/token type—for example, JWT access-token signature, issuer, audience, expiration, and scope, or trusted validation/introspection for opaque/reference tokens. Do not merely check that a credential/token exists, and do not use an OIDC ID Token as an API access token.
Common traps: Treating OAuth 2.0 as a user-authentication protocol. Using an OIDC ID Token directly as an API access token. Checking only that a token exists without validating issuer, audience, expiry, scope, and other applicability requirements.
Distinctions: OIDC = user authentication/identity layer; OAuth 2.0 = authorization framework; API access is normally authorized with an access token