OIDC and SAML
OpenID Connect (OIDC) and Security Assertion Markup Language (SAML) are the two protocols behind single sign-on. Both hand a user from one login to many applications, and both name the same three parts. The differences are age, data format, and vocabulary.
The three parts
- The user, or a program acting as one, wants into an application.
- The identity provider (IdP) checks who the user is.
- The application trusts the IdP’s answer and lets the user in.
Login flow when the user starts at the IdP
- The user logs in to the IdP.
- The user picks an application from the IdP’s list.
- The IdP sends the user’s identity data to the user’s browser.
- The browser passes that data to the application.
- The application checks that the user may use it, then lets the user in.
Login flow when the user starts at the application
- The user opens the application and tries to log in.
- The application redirects the browser to the IdP.
- The IdP logs the user in, or sees that the user is already logged in.
- The IdP confirms the user has access to the application that sent the request.
- The IdP sends the user’s identity data to the browser, which passes it to the application.
- The application checks that the user may use it, then lets the user in.
Same thing, different names
| SAML |
OIDC |
What it is |
| Identity Provider (IdP) |
OpenID Provider (OP) |
The system that authenticates the user |
| Service Provider (SP) |
Relying Party (RP) |
The application the user wants |
| Assertion |
ID token with claims |
The signed identity data sent to the application |
Where they differ
- SAML 2.0 became a standard in 2005. OIDC was published in 2014.
- SAML carries the assertion as signed XML. OIDC carries the claims as a signed JSON Web Token (JWT).
- SAML is its own protocol. OIDC is an identity layer on top of OAuth 2.0, which by itself only grants a program access to an API.
- OIDC uses plain HTTPS calls and JSON, so it fits mobile apps and REST APIs with less code than XML signing needs.
- Both can start at the IdP or at the application.
See also
All entries | Español