OpenID Connect Experts in Germany
in minutes from over 15,000 CVs with the power of AIHire experts who design secure login flows, connect identity providers, and integrate OIDC with OAuth 2.0, SSO, and user identity systems. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used OpenID Connect
Collin Kempkes
Last position:
Lead Fullstack Developer at Freelance
- Development of cloud native applications to provide a multi-vendor marketplace for different digital assets (e.g. NFTs)
- Design and operation of a microservice architecture using Nest.js, MySQL, Redis, Hasura, Algolia, Docker and Serverless
- Design and operation of a streaming data architecture using Kafka (with JSON Schemas)
- Creation of CI/CD pipelines with GitHub Actions for automated deployment of applications
- Testing and evaluating new technologies for more stable, faster, safer and more sustainable application development
- Building the full infrastructure with Terraform in AWS
- Integration of Stripe to handle international payments
- Use of Algolia for real-time search of digital assets on the platform
- Presenting results to stakeholders and running internal meetups
- Federation of services with GraphQL and Hasura
- Discussions about architecture decisions in the IT landscape and their impact
- Use of message queues for app-internal communication and component encapsulation
- Advising internal staff on the implementation of business and technical requirements
- Test Driven Development: unit, integration and E2E testing using JUnit
- Use of Next.js/React with SASS/SCSS for frontend applications
- Use of Vue.js with SASS/SCSS for frontend applications
- Integration of security-related mechanisms (JWT tokens with Auth0, OAuth, OIDC, IP guards, BOLA, secret vaults)
- Creation of microfrontends using Retool for fast prototyping and testing of functionality
- Use of nx monorepo with nrwl
Karen Manukyan
Last position:
Personal AI Engineering Project — Croky AI at Crocky AI
Product:
- Built a production-ready AI platform for generating brand-aware marketing images and videos from product data, user requirements, and uploaded media.
- Own the platform architecture, technical roadmap, API design, security, deployment workflow, operational reliability, and model-provider strategy.
- Developed the core platform in .NET and built supporting AI and workflow prototypes in Python, applying language-independent API contracts and structured interfaces between services and model providers.
- Implemented reliable background processing with RabbitMQ, persisted workflow state, idempotent handling, retries, failure recovery, logging, secure storage, authorization, and credit accounting.
- Made pragmatic build-versus-buy and model-routing decisions based on reliability, latency, cost, and maintainability rather than novelty.
Agent Orchestration & RAG Systems
- Built and compared agent workflows using Microsoft Agent Framework, LangGraph, and LangChain, including tool use, conditional routing, clarification steps, state management, and hand-offs between agents.
- Implemented reusable .NET components for agents, prompts, tools, model providers, structured responses, and retrieval with pyvector, making it easier to change AI providers without rewriting the core workflow.
Sabahattin Kunas
Last position:
Sole responsibility (concept, development, infrastructure, operations) at Own project busik.ch
- Ride-sharing and bus platform, live and working. Backend Spring Boot 4.1 on Java 21, PostgreSQL with Flyway, Testcontainers integration tests. Running in my own AWS account (ECS Fargate, ALB, ECR, IAM least privilege) with CI/CD via GitHub Actions and OIDC federation without static credentials. Development throughout AI-assisted with Claude Code, including my own skills and project-specific memory. Spring Boot · Java 21 · PostgreSQL · Flyway · Docker · AWS ECS/ALB/ECR · CI/CD · GitHub Actions · Claude Code
Ali Aminian
Last position:
Platform Engineer & Software Architect at Yatta GmbH
- Architected the Yatta Integration Layer – a config-driven integration platform on Java 25, Spring Boot 4 (WebFlux), Temporal, gRPC and Kafka, enabling new third-party integrations (e.g. AVS fulfillment) via declarative JSON configs with zero code changes.
- Designed and implemented Tink integration with 0Auth IBAN verification to enhance fraud prevention and account validation workflows with Adyen payByBank.
- Architected and implemented an OpenFGA-based authorization model for centralized management of users, groups, and fine-grained access control in the vendor portal.
- Architected and led delivery of the Yatta API Gateway platform using GraphQL Federation, providing a unified enterprise API layer across distributed microservices with centralized authentication, authorization and request orchestration.
- Replaced NGINX + NLB with Istio service mesh and AWS ALB; rolled out WAF, OAuth (Cognito), IP whitelisting and RBAC across environments.
- Migrated CDC from Confluent Cloud connectors to a self-hosted Kafka Connect + Debezium stack, reducing operational cost by ~80% across multiple environments.
- Implemented the Transactional Outbox pattern with Debezium for reliable, exactly-once event publishing to Kafka with Avro and Schema Registry.
- Migrated dunning/payment-recovery workflows from Airflow to Temporal, achieving 99.9% reliability for settlement handling.
- Optimised Apache Airflow with deferrable sensors to handle 1000+ concurrent DAG runs without scaling the worker pool.
- Refactored a monolithic Terraform codebase into 3 modular projects, cutting deployment time by ~45%.
- Stood up full observability with OpenTelemetry, Tempo, Prometheus and Loki; automated dev/staging/prod with ArgoCD, Image Updater and Helm.
- Collaborated with product, operations and engineering stakeholders to define scalable platform architecture and integration standards aligned with long-term business and operational goals.
Niklas Witzel
Last position:
AI Engineer at Tensora GmbH
- Designed and developed a multi-tenant SaaS platform enabling organizations to build their own knowledge bases and chat with brand-customized AI assistants (white-label approach with dynamic branding per organization).
- Implemented a scalable RAG architecture with a GPT-4o tool-use loop, hybrid semantic search, and strict tenant isolation at database and search index level.
- Built persistent, project-like chat sessions including a streaming API (SSE), multilingual support, and speech input/output (STT/TTS).
- Delivered the cloud infrastructure as Infrastructure-as-Code, fully automated per-customer CI/CD pipelines, and an onboarding process for new tenants.
Technologies used: Python, FastAPI, Pydantic (v2 noted), Next.js, React, TypeScript, Tailwind CSS, OpenAI / LLMs (GPT-4o), Azure AI Search, Cosmos DB, Azure Blob Storage, Azure Cognitive Services Speech, Azure App Service, Azure Container Registry, Retrieval-Augmented Generation (RAG), Server-Sent Events (SSE), Docker, Terraform, GitHub Actions, REST, OpenID Connect (OIDC), Multi-Tenancy
Frédéric Klein
Last position:
Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA
Short description: Leading a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations management while preserving the autonomy of decentralized business units within regulatory frameworks.
Tasks and activities:
Overall responsibility for designing, building, and implementing a company-wide cloud governance structure (Azure), including target picture, roadmap, and operating model.
Managing internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps), including decision and escalation management.
Planning and facilitating workshops on cloud strategy, governance principles, and the design of areas such as identity, connectivity, and platform management.
Defining, implementing, and rolling out cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework based on the Azure Cloud Adoption Framework (CAF), including landing zone and guardrail concepts.
Introducing automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementing cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishing and operationalizing FinOps in an enterprise environment (central and decentralized FinOps teams), including cost management strategies, reporting, and guardrails.
Integrating governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementing access concepts including RBAC design and breaking-glass mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud use in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risk.
Improved operational and decision-making capability across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).
Significantly increased workload compliance during lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure Networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud shared responsibility model.
Hub-and-spoke connectivity / central shared services (from hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, breaking-glass concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Kevin Fischer
Last position:
DevOps and Platform Engineer at DB Systel GmbH
- Error analysis and fixes including performance optimization of the in-house developed platform API
- Change and incident management in day-to-day operations
- Responsible for compliance with security and compliance requirements
- Vendor management for software development and maintenance
- Planning and execution of migration of legacy services to a cloud native platform
Role in the project: project staff, implementation team
Used skills: requirements analysis, IT service and application management, IT operations, error analysis and performance optimization, software maintenance and lifecycle management
Project environment: Cloud Native Platform (Kubernetes, Crossplane, AWS, ArgoCD, Grafana)
Salim Chehab
Last position:
Cloud / Systems Architect
- Development and introduction of operational processes
- Preparation of complete documentation packages (including emergency management and operations) to meet compliance requirements
- Introduction of a workshop on IaC (Infrastructure as Code)
- Professional consulting for the project's security concept (ISMS)
- Installation and operation of Kubernetes clusters on AWS, on-prem, and Azure
- Design of hybrid cloud architecture (on-prem, Hetzner, AWS)
- Analysis and resolution of incidents and system outages
- Network changes to firewall rules, gateways, OpenVPN settings, and IPsec tunnel (pfSense)
- Professional consulting on BitBucket, Jenkins, and GitLab CI/CD pipelines
- Consulting on Ansible deployments and infrastructure automation
- Consulting on building a scalable system in the cloud (AWS / Azure)
- Technologies / Tools: Ansible, Terraform, AWS, Azure, VPN, pfSense, Jenkins, Bitbucket, Kubernetes, GitLab Runner, ISMS, Golang, Prometheus, Grafana, S3, Lambda, RDS, ECS, Cognito, OIDC, Harbor, MinIO, Postgres, Redis, Keycloak, Ceph, Proxmox, CloudFormation, PostgreSQL, Flux CD, Hetzner, IONOS, Sonatype Nexus Repository, Entra ID, Dex IdP, Pulumi
Saqib Javed
Last position:
AI Developer / AI Engineer (Lead) at KOM4TEC GmbH
- Conceptual design and implementation of modular AI assistants for sales and business processes in the Microsoft ecosystem (Agentic AI, Copilot extensions)
- Frontend architecture and development with React + TypeScript for embedded chat and assistant surfaces (streaming UI, hooks, React Query, OpenAPI clients)
- Enterprise-level agent development: reusable skill/agent library, MCP server, review and compliance gates
- LLM integration into the user experience: Anthropic (Claude), OpenAI, tool use, RAG pipelines, prompt engineering, guardrails
- Architecture and code review consulting as well as mentoring in the AI development team
- Integration with Microsoft Graph, Power Platform, and Azure services
- Technologies: React, TypeScript, Anthropic Claude, OpenAI, MCP, RAG, Microsoft Graph, Power Platform, Azure
Tymofii Sukhachov
Last position:
Senior Backend Developer at Medavis
- Developed backend features for Modern RIS, a web-based Radiology Information System integrated with the existing Classic RIS via WebView.
- Worked on a modular Spring Boot backend covering clinical workflows such as appointments, examinations, patients, orders, reporting, billing, and inventory.
- Contributed to event-driven architecture using domain events to decouple workflows across backend modules.
- Implemented REST/OpenAPI endpoints, service-layer business logic, DTO mapping, validation, and integration points for the React frontend.
- Worked with PostgreSQL-backed domain models, Liquibase database changes, read/write model separation, and legacy RIS database structures.
- Integrated authentication and authorization flows using Keycloak and OAuth2.
- Added and maintained unit/integration tests using JUnit, Rest Assured, Testcontainers, and project-specific test utilities.
- Supported CI/CD and local development workflows using Maven, Docker Compose, Jenkins, and generated OpenAPI clients.
Tech stack: Java 21, Spring Boot 3.5, Maven, PostgreSQL, Liquibase, Keycloak, OAuth2, REST, OpenAPI/Springdoc, MapStruct, Lombok, Docker, Testcontainers, Jenkins.
Kyu-Wang Lee
Last position:
Software Architect & Lead Software Engineer at Landesamt für Steuern Niedersachsen
The goal of BIENE is to provide a uniform program for tax collection for all states.
In tax collection, the aim is to collect the assessed taxes. This includes handling due dates, documenting incoming and outgoing payments, triggering reminders or refunds. Statute of limitations and payment reminders also play an important role. All payment transactions with banks and accounting are mapped in BIENE.
Setting up the architecture and coordinating the provisioning of development and test environments at the Hanover location
Installing and configuring environments on Linux servers (Apache Kafka, PostgreSQL)
Interface tasks: coordinating and aligning the integration of software products from other departments and their test data
Upgrading application server, JDK, Maven project structure
Environment coordination and build management
Implementing external interfaces
Implementing business requirements
Designing and implementing RESTful APIs and OpenAPI specifications
Designing and implementing microservice architecture
Setting up and maintaining CI/CD pipelines
Deploying applications on OpenShift
Creating technical documentation and diagrams
Working with SQL databases (Oracle and PostgreSQL)
Setting up authentication and authorization for the application and users
Containerizing the application (automated deployment via CI/CD pipeline)
Khaled Teilab
Last position:
Consultant / DevOps Engineer at Dr. Ing. h.c. F. Porsche Aktiengesellschaft
- Porsche ID is a unified digital identity platform providing secure authentication and seamless access across Porsche’s online services, mobile apps, and connected vehicle features
- Designed and implemented new authentication and authorization functionalities for both users and systems
- Ensured high availability, security, and performance to deliver a flawless digital experience for Porsche customers
- Technologies: Auth0, Angular, Tailwind, AWS, Terraform, Github
- Methodologies: Scrum and SAFe
Thomas Hoefkens
Last position:
Senior MLOps, DevOps Engineer at Trianel Energy
- Build and operate an end-to-end MLOps platform on Azure ML and Kubernetes (Kubeflow) for the automated deployment, monitoring, and scaling of forecasting models (including Temporal Fusion Transformer, Informer, Autoformer).
- Implement CI/CD pipelines in Azure DevOps for the full ML lifecycle – from resource provisioning (Terraform), data transformation (Hugging Face Datasets, Pandas, PyTorch, CUDA cluster) through training and evaluation to model registry and endpoint deployment.
- Integrate MLflow for experiment tracking, model versioning, performance monitoring, and automated registration in the Azure Model Registry.
- Develop and containerize PyTorch training jobs (Azure Notebook, Jupyter Notebooks) for price and time series forecasting (PFC models) with automatic rollout via Azure ML Endpoints and REST/gRPC interfaces, Docker containerization, secured with OAuth 2.0.
- Set up monitoring and alerting mechanisms (Prometheus, MLflow Metrics), log centralization, and cost monitoring.
- Automate infrastructure provisioning and model deployment using Terraform, Helm, and Azure CLI; connect to existing market data systems and event pipelines.
- Migrate existing workloads and databases (IONOS → Azure, MongoDB) with integration into central MLOps workflows and internal networks.
- Extend the platform with LLM-based tools (LangChain, LangServe) to integrate GPT-based analysis modules into existing Spring Boot services for market anomaly detection and automated reports.
- Analyze and architect a software solution to process large volumes of data efficiently (>3000 messages/sec.) (market data store).
- Spring Boot / Java 21 container development with RabbitMQ for distributing stock market data via MongoDB (Kubernetes) with fast storage of data in Redis RMaps, deduplication, forwarding messages to Read Model queues, and building Read Models for UI display in MongoDB.
- Integration of RESTHeart to create a REST API for MongoDB.
- Build an Angular frontend to simplify data queries and master data maintenance.
- Agentic coding with remote and local LLMs (Claude Sonnet, Ollama Qwen) and MCP servers.
- Develop Python scripts for transforming and cleaning incoming stock market data (Pandas, scikit-learn).
Julius Herrera Glomm
Last position:
Freelancer at Freelancer — Pharma Industry
- Led migration to GCP using Terraform, GKE, and GitOps, improving deployment consistency and scalability
- Implemented Datadog observability stack via Terraform and datadog-operator
- Established automated end-to-end tests and on-call processes, improving incident response and service reliability
- Migrated from NGINX Ingress Controller to Kubernetes Gateway API (NGINX Gateway Fabric)
- Migrated stateful services (PostgreSQL and Redis) to GCP, improving scalability and operational reliability
Srinivasu Kakaraparti
Last position:
Atruvia
Project: Tax Exemption Order Application
The client has an existing application for creating and maintaining tax exemption orders for end customers; design and implementation of a comparable application for internal employees.
- Design and implementation of microservices and the UI for the business area "tax exemption orders" using Domain Driven Design as well as Spring Boot and Angular.
- Implementation of reactive, non-reactive, and asynchronous APIs (Spring REST, WebFlux, GraphQL).
- Development of the Angular application, including state management using Signals, RxJS Observables, and subscriptions.
- Securing the API and the application using OAuth2, JWT, and OpenID Connect.
- Configuration and setup of CI/CD pipelines with Jenkins.
- Collaboration with cross-functional teams and conducting code reviews.
Environment: Java, Spring Boot, Angular 18 & 19 (standalone, signals), RxJs, Bootstrap CSS, Vitesting, OpenShift, Istio, microservices, Kafka, Dynatrace, Jenkins, GitLab, Graylog, Sonar, Oauth2, OracleDB
Discover over 15,000 top freelancers
Statistics of experts using OpenID Connect
Aggregated from the professional profiles of matched freelancers.
Experience
20 years
Position duration
2 years
Positions per freelancer
14
Top business areas
Information Technology, Product Development, Project Management
Top industries
Information Technology, Banking and Finance, Retail
Certification focus areas
Information Technology, Product Development, Project Management
Bachelor's degree or higher
83%
Master's degree or higher
53%
Doctorate
7%
Certifications per freelancer
2
Most common languages
German, English, French
Speak two or more languages
94%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using OpenID Connect
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Identity flow
OpenID Connect is the layer that turns authentication into a clean, standards-based login flow. It sits on top of OAuth 2.0 and lets apps verify who a user is through an identity provider. Companies use it for sign-in, single sign-on, and account linking across web and mobile products.
Common work
- Add login via OpenID Connect and OIDC discovery
- Connect apps to identity providers such as Keycloak, Auth0, Okta, Azure AD, or Ping
- Validate ID tokens, claims, scopes, and session handling
- Support logout, refresh flows, and account recovery
- Review redirects, callback URLs, and security settings
Where it fits
OIDC shows up in customer portals, internal tools, SaaS products, and partner integrations. It is also common in regulated environments where access control and traceable identity matter. In Germany, teams often need experts who can work with local IT, security, and product groups in clear English or German.
Tooling and stack
Strong specialists know the standards behind the flow, not just the library in front of them. They work with JWT, JWK, discovery documents, PKCE, role mapping, and session management. They also understand how OIDC connects with OAuth 2.0, SAML, and directory systems.
Why bring in freelance help
Companies often need outside help when a login flow is blocking release work, an identity provider migration is risky, or token validation has become messy across services. Freelance experts are also useful for audits, architecture reviews, and implementation support when internal teams need a focused hand. The best professionals leave behind code, clear settings, and simple runbooks.
What strong experts do
A strong OIDC specialist keeps authentication strict and simple. They check issuer, audience, nonce, and redirect handling, then make sure claims are mapped the same way across environments. They document the flow so product, security, and operations teams can maintain it without guesswork.
Frequently asked questions
Need clarity? These are the questions we hear most often about OpenID Connect.
OpenID Connect is used for login, single sign-on, and identity verification across apps and services. Teams use it when they want one secure sign-in flow for web apps, mobile apps, APIs, and partner access. It is especially common when the product needs a standard way to trust an external identity provider.
OIDC adds identity on top of OAuth 2.0, so it is the usual choice when the project needs authentication, not just authorization. Compared with SAML, it is lighter and better aligned with modern app stacks, especially for web and mobile products. Many companies still need both in the same environment, so a freelancer should understand the bridge between them.
A strong OpenID Connect expert usually works with providers such as Keycloak, Auth0, Okta, Azure AD, or Ping. They should also know JWT, JWK, PKCE, discovery documents, and session handling. If your setup includes directories or legacy sign-in, experience with SAML and OAuth 2.0 is a plus.
Companies usually bring in OpenID Connect help when sign-in is blocking delivery, token handling is failing in production, or an identity provider migration needs care. It is also common during security reviews, app modernization, or when different teams have implemented the flow in different ways. A freelancer can stabilize the setup and leave clear implementation notes.
A OpenID Connect project needs someone who has handled the full flow before, not only read the spec. Simple integrations may be straightforward, but production work often includes token validation, logout, redirect rules, and claim mapping across services. If the app is customer-facing or security-sensitive, you want proven hands-on experience.
Yes, OIDC work is well suited to remote collaboration because most tasks are configuration, code review, and integration testing. In Germany, companies often mix remote specialists with local product, security, and platform teams. Clear written communication helps a lot, especially when handoffs cross time zones or language groups.
A good OpenID Connect specialist explains the flow clearly and checks the important details: issuer, audience, nonce, redirect URIs, scopes, and token expiry. They should also be able to explain why a design is safe, not just make the login work. Look for clean documentation and a setup that your team can maintain.
A careful OpenID Connect freelancer should ask which identity provider is in use, what the app stack looks like, and whether the project needs SSO, migration, or a new integration. They should also clarify environments, callback URLs, logout behavior, and who owns security approval. Those details prevent delays and avoid rework.
The average hourly rate of freelancers in Germany who have used OpenID Connect in their recent projects is 98 €, which corresponds to a daily rate of about 781 € based on an 8-hour working day.
Of the freelancers in Germany who have used OpenID Connect in their recent projects, 83% hold at least a Bachelor's degree, 53% hold at least a Master's degree, and 7% hold a doctorate.
On average, freelancers in Germany who have used OpenID Connect in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2 years.
The most common languages among freelancers in Germany who have used OpenID Connect in their recent projects are German (98%), English (92%), and French (18%).
The most common industries among freelancers in Germany who have used OpenID Connect in their recent projects are Information Technology (98%), Banking and Finance (56%), and Retail (42%).
The most common business areas among freelancers in Germany who have used OpenID Connect in their recent projects are Information Technology (100%), Product Development (91%), and Project Management (66%).
Main locations of FRATCH Experts, who have recently used OpenID Connect
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Frankfurt