<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Oauth on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/oauth/</link><description>Recent content in Oauth on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:22:17 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/oauth/index.xml" rel="self" type="application/rss+xml"/><item><title>OAuth vs SAML: Authorization Framework or XML-Based SSO Standard</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-oauth-vs-saml-authorization-framework-or-xml-based-sso-stand/</link><pubDate>Mon, 03 Aug 2026 04:22:17 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-oauth-vs-saml-authorization-framework-or-xml-based-sso-stand/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;OAuth and SAML both let one system vouch for a user to another, but they solve different problems: OAuth is an &lt;strong class="kw"&gt;authorization&lt;/strong&gt; framework built to grant apps limited access to APIs, while SAML is an &lt;strong class="kw"&gt;XML-based&lt;/strong&gt; standard built for enterprise single sign-on. Picking the wrong one means using a token-delegation protocol for an identity-federation problem, or vice versa.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="130" y="28" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--compare-a)"&gt;OAuth&lt;/text&gt;&lt;text x="130" y="46" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;delegated authorization&lt;/text&gt;&lt;text x="510" y="28" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--compare-b)"&gt;SAML&lt;/text&gt;&lt;text x="510" y="46" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;federated authentication&lt;/text&gt;&lt;line x1="320" y1="56" x2="320" y2="345" stroke-dasharray="4 4" style="stroke:var(--border)" stroke-width="1.5"/&gt;&lt;rect x="60" y="62" width="140" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="87" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Client App&lt;/text&gt;&lt;line x1="130" y1="102" x2="130" y2="140" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="125,138 135,138 130,148" style="fill:var(--compare-a)"/&gt;&lt;rect x="60" y="148" width="140" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="170" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Authorization&lt;/text&gt;&lt;text x="130" y="183" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="130" y1="188" x2="130" y2="226" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="125,224 135,224 130,234" style="fill:var(--compare-a)"/&gt;&lt;rect x="60" y="234" width="140" height="40" rx="4" stroke-dasharray="3 3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="252" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Access Token&lt;/text&gt;&lt;text x="130" y="265" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;{ JSON }&lt;/text&gt;&lt;line x1="130" y1="274" x2="130" y2="304" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="125,302 135,302 130,312" style="fill:var(--compare-a)"/&gt;&lt;rect x="60" y="312" width="140" height="36" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="334" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Resource API&lt;/text&gt;&lt;rect x="440" y="62" width="140" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="510" y="87" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service Provider&lt;/text&gt;&lt;line x1="510" y1="102" x2="510" y2="140" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="505,138 515,138 510,148" style="fill:var(--compare-b)"/&gt;&lt;rect x="440" y="148" width="140" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="510" y="172" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Identity Provider&lt;/text&gt;&lt;line x1="510" y1="188" x2="510" y2="226" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="505,224 515,224 510,234" style="fill:var(--compare-b)"/&gt;&lt;rect x="440" y="234" width="140" height="40" rx="4" stroke-dasharray="3 3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="510" y="252" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;SAML Assertion&lt;/text&gt;&lt;text x="510" y="265" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;&amp;lt;XML&amp;gt;&lt;/text&gt;&lt;line x1="510" y1="274" x2="510" y2="304" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="505,302 515,302 510,312" style="fill:var(--compare-b)"/&gt;&lt;rect x="440" y="312" width="140" height="36" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="510" y="334" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;SP Session&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;OAuth&lt;/th&gt;
&lt;th&gt;SAML&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Authorization - grants an app limited, scoped access to resources&lt;/td&gt;
&lt;td&gt;Authentication - proves a user&amp;rsquo;s identity for single sign-on&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Assertion/token format&lt;/td&gt;
&lt;td&gt;JSON, most commonly a JWT access token&lt;/td&gt;
&lt;td&gt;XML, a digitally signed SAML assertion&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flow initiation&lt;/td&gt;
&lt;td&gt;Client app redirects the user to an authorization server to request consent&lt;/td&gt;
&lt;td&gt;Service provider redirects the user to an identity provider to authenticate&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential delivery&lt;/td&gt;
&lt;td&gt;Access token returned via redirect or back-channel to the client&lt;/td&gt;
&lt;td&gt;Signed assertion POSTed back to the service provider&amp;rsquo;s endpoint&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transport mechanism&lt;/td&gt;
&lt;td&gt;REST/HTTP calls carrying a bearer token in the Authorization header&lt;/td&gt;
&lt;td&gt;HTTP redirect and POST bindings, historically also SOAP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Session establishment&lt;/td&gt;
&lt;td&gt;Client presents the token on each API call to prove access rights&lt;/td&gt;
&lt;td&gt;Service provider validates the assertion once and creates a local session&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lifetime and renewal&lt;/td&gt;
&lt;td&gt;Short-lived access tokens paired with long-lived refresh tokens&lt;/td&gt;
&lt;td&gt;Assertions tied to the SSO session with no built-in refresh mechanism&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical ecosystem&lt;/td&gt;
&lt;td&gt;Mobile apps, SPAs, and third-party API integrations (Google, GitHub)&lt;/td&gt;
&lt;td&gt;Enterprise SSO into web apps via IdPs like Okta, ADFS, or Azure AD&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OAuth is fundamentally an &lt;strong class="kw"&gt;authorization&lt;/strong&gt; framework, not an identity protocol, though OpenID Connect layers authentication on top of it.&lt;/li&gt;
&lt;li&gt;SAML assertions are &lt;strong class="kw"&gt;XML&lt;/strong&gt;-based and signed, while OAuth tokens are typically &lt;strong class="kw"&gt;JSON&lt;/strong&gt;, often as a JWT.&lt;/li&gt;
&lt;li&gt;SAML is built around browser &lt;strong class="kw"&gt;redirects&lt;/strong&gt; and POST bindings for SSO, while OAuth is built around bearer tokens for API calls.&lt;/li&gt;
&lt;li&gt;OAuth supports &lt;strong class="kw"&gt;refresh tokens&lt;/strong&gt; for renewing access; SAML assertions have no native renewal and rely on re-authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;OAuth&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>