Identity Provider (IdP)

An Identity Provider (IdP) is a system that manages digital identities and handles the authentication of users. Applications rely on the identity verification of the IdP instead of operating their own login procedures.

After a successful login, the IdP issues signed proofs – assertions according to SAML or tokens according to OpenID Connect – which connected applications verify and accept. The identity provider is thus the technical basis for single sign-on and identity federation. At the same time, it enforces central security policies, such as multi-factor authentication or context-dependent access rules, and connects directory services and HR sources for this purpose.

Especially in cloud and SaaS environments, the IdP concentrates login security in one place: this simplifies administration and the user experience, but also makes it a highly critical system whose protection has the highest priority. The identity provider is thus the central instance of every Identity Security architecture.