OAuth & OIDC & JWT interview questions

69 OAuth & OIDC & JWT questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is OAuth 2.0?

Junior
  1. A.long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.JWT attack where the signature algorithm is set to none so an unsigned token is wrongly accepted
  3. C.OAuth mechanism limiting the specific permissions an access token grants to a resource
  4. D.authorization framework letting an app obtain delegated access to resources without sharing credentials

Answer + AI explanation with Pro

2. Which term means: "authorization framework letting an app obtain delegated access to resources without sharing credentials"?

Junior
  1. A.Token introspection
  2. B.OAuth 2.0
  3. C.Bearer token
  4. D.JWT

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.OAuth 2.0 — JWT attack where the signature algorithm is set to none so an unsigned token is wrongly accepted
  2. B.OAuth 2.0 — deprecated OAuth flow returning tokens directly in the redirect URL, vulnerable to leakage
  3. C.OAuth 2.0 — accepting a token minted for a different audience, enabling cross-service token reuse
  4. D.OAuth 2.0 — authorization framework letting an app obtain delegated access to resources without sharing credentials

Answer + AI explanation with Pro

4. What is OpenID Connect (OIDC)?

Junior
  1. A.long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  3. C.statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)
  4. D.JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature

Answer + AI explanation with Pro

5. Which term means: "authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity"?

Junior
  1. A.OpenID Connect (OIDC)
  2. B.Token revocation
  3. C.Token introspection
  4. D.ID token

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.OpenID Connect (OIDC) — authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  2. B.OpenID Connect (OIDC) — statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)
  3. C.OpenID Connect (OIDC) — endpoint a resource server calls to check whether a token is active and its associated metadata
  4. D.OpenID Connect (OIDC) — OIDC token (a JWT) asserting the authenticated user's identity to the client application

Answer + AI explanation with Pro

7. What is JWT?

Junior
  1. A.long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.authorization framework letting an app obtain delegated access to resources without sharing credentials
  3. C.JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature
  4. D.JSON Web Encryption, a JWT variant whose payload is encrypted rather than merely signed

Answer + AI explanation with Pro

8. Which term means: "JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature"?

Junior
  1. A.Refresh token
  2. B.JWT
  3. C.Refresh token rotation
  4. D.Token introspection

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.JWT — authorization framework letting an app obtain delegated access to resources without sharing credentials
  2. B.JWT — Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients
  3. C.JWT — JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature
  4. D.JWT — opaque value tying an OAuth authorization request to its callback to prevent CSRF

Answer + AI explanation with Pro

10. What is Access token?

Junior
  1. A.JWT attack where the signature algorithm is set to none so an unsigned token is wrongly accepted
  2. B.Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients
  3. C.invalidating a token before its expiry, typically via a revocation endpoint or denylist
  4. D.credential representing granted authorization that a client presents to access a protected resource

Answer + AI explanation with Pro

11. Which term means: "credential representing granted authorization that a client presents to access a protected resource"?

Junior
  1. A.Access token
  2. B.OAuth 2.0
  3. C.Client Credentials flow
  4. D.OpenID Connect (OIDC)

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Access token — authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  2. B.Access token — JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature
  3. C.Access token — credential representing granted authorization that a client presents to access a protected resource
  4. D.Access token — deprecated OAuth flow returning tokens directly in the redirect URL, vulnerable to leakage

Answer + AI explanation with Pro

13. What is ID token?

Junior
  1. A.endpoint a resource server calls to check whether a token is active and its associated metadata
  2. B.OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request
  3. C.Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients
  4. D.OIDC token (a JWT) asserting the authenticated user's identity to the client application

Answer + AI explanation with Pro

14. Which term means: "OIDC token (a JWT) asserting the authenticated user's identity to the client application"?

Junior
  1. A.Client Credentials flow
  2. B.PKCE
  3. C.ID token
  4. D.Token audience confusion

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.ID token — long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.ID token — accepting a token minted for a different audience, enabling cross-service token reuse
  3. C.ID token — OIDC token (a JWT) asserting the authenticated user's identity to the client application
  4. D.ID token — opaque value tying an OAuth authorization request to its callback to prevent CSRF

Answer + AI explanation with Pro

16. What is Refresh token?

Junior
  1. A.long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  3. C.JSON Web Encryption, a JWT variant whose payload is encrypted rather than merely signed
  4. D.OAuth mechanism limiting the specific permissions an access token grants to a resource

Answer + AI explanation with Pro

17. Which term means: "long-lived credential used to obtain new access tokens without re-authenticating the user"?

Junior
  1. A.Refresh token
  2. B.JWT claims
  3. C.OpenID Connect (OIDC)
  4. D.JWKS

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Refresh token — long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.Refresh token — deprecated OAuth flow returning tokens directly in the redirect URL, vulnerable to leakage
  3. C.Refresh token — authorization framework letting an app obtain delegated access to resources without sharing credentials
  4. D.Refresh token — Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients

Answer + AI explanation with Pro

19. What is Authorization Code flow?

Mid
  1. A.OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request
  2. B.Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients
  3. C.JSON Web Encryption, a JWT variant whose payload is encrypted rather than merely signed
  4. D.deprecated OAuth flow returning tokens directly in the redirect URL, vulnerable to leakage

Answer + AI explanation with Pro

20. Which term means: "OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request"?

Mid
  1. A.Scope
  2. B.JWT claims
  3. C.Authorization Code flow
  4. D.ID token

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Authorization Code flow — authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  2. B.Authorization Code flow — prompt where a resource owner approves the specific scopes an app is requesting
  3. C.Authorization Code flow — OAuth flow for machine-to-machine access where the app authenticates as itself with no user
  4. D.Authorization Code flow — OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request

Answer + AI explanation with Pro

22. What is JWT claims?

Mid
  1. A.long-lived credential used to obtain new access tokens without re-authenticating the user
  2. B.OAuth mechanism limiting the specific permissions an access token grants to a resource
  3. C.credential representing granted authorization that a client presents to access a protected resource
  4. D.statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)

Answer + AI explanation with Pro

23. Which term means: "statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)"?

Mid
  1. A.alg:none vulnerability
  2. B.Access token
  3. C.JWT claims
  4. D.Token audience confusion

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.JWT claims — OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request
  2. B.JWT claims — JSON Web Key Set endpoint publishing the public keys clients use to verify a token's signature
  3. C.JWT claims — statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)
  4. D.JWT claims — prompt where a resource owner approves the specific scopes an app is requesting

Answer + AI explanation with Pro

25. What is Scope?

Mid
  1. A.JSON Web Token, a signed (and optionally encrypted) token with header, payload claims, and signature
  2. B.OAuth flow where the client exchanges a short-lived code for tokens via a back-channel request
  3. C.OIDC token (a JWT) asserting the authenticated user's identity to the client application
  4. D.OAuth mechanism limiting the specific permissions an access token grants to a resource

Answer + AI explanation with Pro

26. Which term means: "OAuth mechanism limiting the specific permissions an access token grants to a resource"?

Mid
  1. A.Consent screen
  2. B.Refresh token rotation
  3. C.alg:none vulnerability
  4. D.Scope

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Scope — Proof Key for Code Exchange, an extension protecting the authorization code flow against interception, required for public clients
  2. B.Scope — accepting a token minted for a different audience, enabling cross-service token reuse
  3. C.Scope — credential representing granted authorization that a client presents to access a protected resource
  4. D.Scope — OAuth mechanism limiting the specific permissions an access token grants to a resource

Answer + AI explanation with Pro

28. What is Bearer token?

Mid
  1. A.authentication layer built on OAuth 2.0 that adds an ID token proving the user's identity
  2. B.statements in a token payload such as iss (issuer), sub (subject), aud (audience), and exp (expiry)
  3. C.token granting access to whoever presents it, requiring transport encryption and careful storage
  4. D.OAuth mechanism limiting the specific permissions an access token grants to a resource

Answer + AI explanation with Pro

29. Which term means: "token granting access to whoever presents it, requiring transport encryption and careful storage"?

Mid
  1. A.OpenID Connect (OIDC)
  2. B.alg:none vulnerability
  3. C.Bearer token
  4. D.Access token

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Bearer token — token granting access to whoever presents it, requiring transport encryption and careful storage
  2. B.Bearer token — OAuth flow for machine-to-machine access where the app authenticates as itself with no user
  3. C.Bearer token — JWT attack where the signature algorithm is set to none so an unsigned token is wrongly accepted
  4. D.Bearer token — Demonstrating Proof-of-Possession that binds a token to a client key so a stolen token is unusable

Answer + AI explanation with Pro

Showing 30 of 69 OAuth & OIDC & JWT questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every OAuth & OIDC & JWT question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers