Answers
What is the difference between SAML and OIDC?
In short
SAML is an older XML-based federation standard; OIDC is a modern JSON/REST identity layer built on OAuth 2.0. Both are used for SSO, but OIDC is the default for new builds and mobile/SPA flows.
Short answer
SAML is an older XML-based federation standard; OIDC is a modern JSON/REST identity layer built on OAuth 2.0. Both are used for SSO, but OIDC is the default for new builds and mobile/SPA flows.
What this actually means in practice
Enterprise IT often still mandates SAML for legacy reasons. New apps should ship OIDC first and add SAML where required for enterprise sales. Both must validate signatures, audiences and expiry.
The most common pitfall
Bespoke 'SSO' that only works for one IdP and breaks the next enterprise procurement.
What to do next
Standardise on OIDC first, add SAML by exception, and validate everything end-to-end.
Frequently asked questions
Does Forth Systems help with this?
Yes — Forth Systems works with banks, payment institutions, insurers and infrastructure operators on exactly this kind of work. Engagements start with a fixed-scope assessment so you see the shape before committing.
How experienced is the team?
Engagements are staffed by named, UK-based senior engineers — not a rotating offshore pool. References from the second line of comparable clients are available on request.
Where are you based?
Edinburgh-based, delivering UK-wide with onsite presence in London and across Scotland as required.
How fast can we start?
Most engagements start within 2-4 weeks of a signed SoW, faster where an existing supplier framework is in place.
