Bits

OIDC and SAML

OpenID Connect (OIDC) and Security Assertion Markup Language (SAML) are the two protocols behind single sign-on. Both hand a user from one login to many applications, and both name the same three parts. The differences are age, data format, and vocabulary.

The three parts

Login flow when the user starts at the IdP

  1. The user logs in to the IdP.
  2. The user picks an application from the IdP’s list.
  3. The IdP sends the user’s identity data to the user’s browser.
  4. The browser passes that data to the application.
  5. The application checks that the user may use it, then lets the user in.

Login flow when the user starts at the application

  1. The user opens the application and tries to log in.
  2. The application redirects the browser to the IdP.
  3. The IdP logs the user in, or sees that the user is already logged in.
  4. The IdP confirms the user has access to the application that sent the request.
  5. The IdP sends the user’s identity data to the browser, which passes it to the application.
  6. The application checks that the user may use it, then lets the user in.

Same thing, different names

SAML OIDC What it is
Identity Provider (IdP) OpenID Provider (OP) The system that authenticates the user
Service Provider (SP) Relying Party (RP) The application the user wants
Assertion ID token with claims The signed identity data sent to the application

Where they differ

See also

All entries | Español