This document discusses using OpenID Connect for mission critical push-to-talk (MCPTT) authentication. It proposes using OpenID Connect to authenticate MCPTT users and issue tokens to allow access to various MCPTT backend services like the key management server, group management server and configuration management server. The tokens would be signed JSON Web Tokens (JWTs) containing claims about the user identity and authorization scope. Symmetric keys would also be distributed to enable encrypted communication between the client and backend services.