OIDC is based on Oauth2. The auth part of Oauth stands for authorization, not authentication which brings me to the problem I have with OIDC - namely OIDC is about granting external party access to your data. You can mitigate this a bit via using something like Okta, which just does not have this data, but lets say you don't have Okta and all you have is Google Workspace.
ratiolat · · focus · HN ↗