The OIDC "id token" is a JWT that contains identity assertions, just like SAML would. You can go fetch the profile via HTTP, but that's mostly because major providers have quietly conceded that JWT is a nightmare, and encoded that fact in their API.
And If they don’t like JWT, why don’t they use something else?
They can't walk JWT back now without breaking existing apps, because parsing it yourself was advertised as an option.