Understand federation and single sign-on
Learn how identity providers make authentication assertions to other services.
- Explain identity federation, single sign-on, and the difference between authentication and delegated access.
In federated identity, one organization’s identity provider (IdP) authenticates a user and provides an assertion to a separately administered relying party. Single sign-on (SSO) lets a user access multiple services through an identity provider session. OAuth is primarily an authorization framework for delegated access; OpenID Connect adds an identity layer on OAuth 2.0. A relying party must validate assertions, audience, issuer, and other protocol requirements.
A small example
1identity_provider = "company IdP"
2service = "expense app"
3assertion = {"issuer": identity_provider, "subject": "user-42", "audience": service}
4print(assertion["issuer"], "asserts identity to", assertion["audience"])company IdP asserts identity to expense app
Federation reduces separate credentials but introduces trust relationships and configuration requirements. Validate signatures and protocol fields, use secure redirects, and scope delegated access. Do not treat an OAuth access token as an identity assertion unless the protocol and validation rules make it one.
Key takeaways
Explain identity federation, single sign-on, and the difference between authentication and delegated access.
Treat access as a lifecycle: grant deliberately, review regularly, and revoke promptly.
Lesson quiz
5 questions · pass with 4 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…