Standards you’ll use every day

StandardPurposeCore Docs
SAML 2.0Federated SSO with signed XML assertionsOASIS SAML 2.0
OAuth 2.0Delegated authorization (scopes, access tokens)RFC 6749, 6750
OpenID Connect 1.0Authentication layer on top of OAuth 2.0OIDC Core, Discovery, Dynamic Reg
JOSE (JWS/JWE/JWK)Signing and encryption for JWTsRFC 7515–7518

Tip: Prefer OIDC for browser-based auth today; use SAML where heritage vendors or SaaS require it.