What is Identity Provider (IdP)?
An identity provider (IdP) is the party in an identity federation that establishes an authentication event for a subscriber and creates a verifiable assertion for a relying party. The IdP can supply selected identity attributes. The relying party validates the assertion, creates its own session, and makes its own access decisions. In OpenID Connect, the OpenID Provider is the IdP and the ID token carries the authentication assertion.
Why it matters
Federation lets applications rely on one managed authentication service instead of issuing and verifying a separate authenticator for each application. This can improve single sign-on, account lifecycle control, and authentication consistency.
How it works
- The relying party sends a federation authentication request to an IdP that it trusts for the transaction.
- The IdP authenticates the subscriber and creates an assertion for the intended relying party with the permitted attributes.
- The relying party validates the issuer, audience, signature, time limits, and protocol state before it creates a session and applies authorization policy.
Example
An employee opens an application behind Pomerium. Pomerium sends the employee to its Hosted Authenticate Service or to the operator's configured OIDC provider. Pomerium validates the authentication result and uses verified claims in route policy.
Pomerium boundary
The Pomerium proxy is not an identity provider. Pomerium's Hosted Authenticate Service provides a hosted IdP, and an operator can instead configure an OIDC-compatible IdP. Pomerium stores relevant session data and uses verified identity claims when it evaluates authorization for a protected route.
Limits and non-claims
- A compromised IdP or incorrect subscriber record can affect every relying party that trusts it.
- An authentication assertion does not decide what the relying party should authorize.
- Federation requires careful issuer, audience, key, redirect, attribute-release, session, and recovery controls.
Evaluation checklist
- Which identity proofing, authenticator, session, and claim process does the provider own?
- Does the relying party validate issuer, audience, protocol response, and local account mapping?
- How do provider compromise, outage, stale claims, recovery, and logout affect relying parties?
