<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Oidc on Osmar Petry</title><link>https://osmarpetry.dev/tags/oidc/</link><description>Recent content in Oidc on Osmar Petry</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 21 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://osmarpetry.dev/tags/oidc/rss.xml" rel="self" type="application/rss+xml"/><item><title>PixieShop Authentication Playbook — OIDC SSO Across Four Identity Providers</title><link>https://osmarpetry.dev/blog/sso-authentication-playbook/</link><pubDate>Sat, 21 Mar 2026 00:00:00 +0000</pubDate><guid>https://osmarpetry.dev/blog/sso-authentication-playbook/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Scenario.&lt;/strong&gt; PixieShop is a B2B SaaS that sells enchanted toys to retail partners. Every partner logs in through their own corporate identity provider — some use Okta, others use Microsoft Entra ID. We never see a password. FusionAuth sits in the middle as our OIDC identity broker, and Auth.js v5 handles the Next.js session on the frontend. This playbook is the single place where we document how the whole chain works, from RSA key creation to federated logout.&lt;/p&gt;</description></item></channel></rss>