SSO Without Giving the Server Your Keys
You redirect to an identity provider, it tells you who the person is, you mint a session. Then you try it on an app that encrypts everything in the browser, and the whole thing falls over.

You redirect to an identity provider, it tells you who the person is, you mint a session. Then you try it on an app that encrypts everything in the browser, and the whole thing falls over.

You redirect to an identity provider, it tells you who the person is, you mint a session.
Both are telling the truth, and neither one helps, because an OIDC token is an assertion about identity — it is not, and cannot be, the key that decrypts Alice's data.
Then you try it on an app that encrypts everything in the browser, and the whole thing falls over.
The page is ready to read now. The fuller skim-friendly version will appear here automatically.
You redirect to an identity provider, it tells you who the person is, you mint a session. Then you try it on an app that encrypts everything in the browser, and the whole thing falls over. The server stores ciphertext and a hash of auth_token, and that is the entire extent of what it knows.
Something a device holds — a passkey, or a key in browser storage.
Open the app view to save this story, compare related coverage, and continue from the same source.