Skip to main content

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

What is Identity Provider (IdP)?

An identity provider (IdP) is the party in an identity federation that establishes an authentication event for a subscriber and creates a verifiable assertion for a relying party. The IdP can supply selected identity attributes. The relying party validates the assertion, creates its own session, and makes its own access decisions. In OpenID Connect, the OpenID Provider is the IdP and the ID token carries the authentication assertion.

Why it matters

Federation lets applications rely on one managed authentication service instead of issuing and verifying a separate authenticator for each application. This can improve single sign-on, account lifecycle control, and authentication consistency.

How it works

  1. The relying party sends a federation authentication request to an IdP that it trusts for the transaction.
  2. The IdP authenticates the subscriber and creates an assertion for the intended relying party with the permitted attributes.
  3. The relying party validates the issuer, audience, signature, time limits, and protocol state before it creates a session and applies authorization policy.

Example

An employee opens an application behind Pomerium. Pomerium sends the employee to its Hosted Authenticate Service or to the operator's configured OIDC provider. Pomerium validates the authentication result and uses verified claims in route policy.

Pomerium boundary

The Pomerium proxy is not an identity provider. Pomerium's Hosted Authenticate Service provides a hosted IdP, and an operator can instead configure an OIDC-compatible IdP. Pomerium stores relevant session data and uses verified identity claims when it evaluates authorization for a protected route.

Limits and non-claims

  • A compromised IdP or incorrect subscriber record can affect every relying party that trusts it.
  • An authentication assertion does not decide what the relying party should authorize.
  • Federation requires careful issuer, audience, key, redirect, attribute-release, session, and recovery controls.

Evaluation checklist

  • Which identity proofing, authenticator, session, and claim process does the provider own?
  • Does the relying party validate issuer, audience, protocol response, and local account mapping?
  • How do provider compromise, outage, stale claims, recovery, and logout affect relying parties?

Sources and further reading

Keep learning

Identity and AuthenticationStandards and Protocols

OpenID Connect (OIDC)

OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.

Learn this term
Identity and Authentication

Single Sign-On (SSO)

SSO lets a user authenticate through one identity service and then access several relying applications without entering credentials at each application.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo