I am glad to see this advice. At CoreOS we have now built API servers, command line tools, and web apps using OpenID Connect and are happy with its development in Open Source and third-party services as well.
> OAuth2 was left generic so that it could be applied to many authorization requirements,
When we started developing Dex[1] we lovingly referred to OpenID as "OAUTH 2.0 with types".
Overall, from integrating OpenID Connect into our products, enabling Kubernetes[2] to use OpenID Connect Providers, and building both an OpenID Connect provider and clients we are pretty happy with the choice we made.
My only complaint is the name of OpenID Connect is simply confusing.
[1] https://github.com/coreos/dex [2] http://kubernetes.io/docs/admin/authentication/#openid-conne...