---
title: "Identity | Dhruv Doshi"
description: "OAuth 2.0 and OIDC, SSO and SCIM, phishing-resistant authentication, and the enterprise identity lifecycle."
canonical: https://doshidhruv.com/topics/identity/
author: Dhruv Doshi
---

[Skip to content](#main-content)

[Dhruv Doshi](/)

[Work](/projects)[Experience](/resume)[Notes](/notes)[Guides](/guides)[Research](/research)[Investing](/investing)[About](/about)[Contact](/contact)[Search /](/search)dark mode

# Identity

OAuth 2.0 and OIDC, SSO and SCIM, phishing-resistant authentication, and the enterprise identity lifecycle.

- ["Phishing-resistant authentication: MFA that actually holds up"](/notes/phishing-resistant-authentication-mfa-that-actually-holds-up) · Note · "We have MFA" is the most common false confidence in authentication. SMS codes, TOTP apps, and push approvals all count as multi factor, and all of them fail against a phishing page…
- ["OAuth 2.0 and OIDC in production: flows, tokens, and the mistakes that repeat"](/notes/oauth-2-0-and-oidc-in-production-flows-tokens-and-the-mistakes-that-repeat) · Note · OAuth 2.0 is an authorization framework that the industry uses for authentication anyway, usually by bolting OpenID Connect on top. The specs are readable, the libraries are mature, and…
- ["SSO and SCIM: the enterprise identity lifecycle nobody designs for"](/notes/sso-and-scim-the-enterprise-identity-lifecycle-nobody-designs-for) · Note · Enterprise buyers ask for SSO on the first sales call, and most engineering teams treat it as the whole identity problem. SSO is sign in — a single arrow pointing into your application.…

**Dhruv Doshi** · Toronto, Canada · [work@doshidhruv.com](mailto:work@doshidhruv.com)

[Resume](/resume)[Notes](/notes)[Guides](/guides)[Topics](/topics)[Search](/search)[Research](/research)[Investing](/investing)[LinkedIn](https://www.linkedin.com/in/dhruvdoshi25071999)[GitHub](https://github.com/DhruvDoshi)

[Sitemap](/sitemap.xml)[RSS](/feed.xml)[LLMs](/llms.txt)

© 2026 Dhruv Doshi
