Why this matters
Federation is where single sign-on gets its strength and where it quietly breaks: an assertion valid for eight hours, a service provider that never checks the audience, a SHA-1 signature, a certificate nobody remembers until sign-ins fail on a Monday morning.
On the OAuth side, wildcard redirect URIs, implicit grant and the password grant are still common, and each turns a small mistake into stolen tokens.