What does a relying party still have to manage about its users when identities come from an IdP?
The RP keeps a user record with application-specific settings, data and rights, which needs at least one unique identifier and a link to one or more digital identities used for authentication.
* The relying party's own user record and the link that ties it to the digital identity at the identity provider. *
Even with a central IdP the application does not become stateless about its users. For Alice the university's learning system holds:
| RP user record (application-specific) | Linked digital identity at the IdP |
|---|---|
| Identifier 1234 | Identifier alice |
| Programme: computer science | Name, first name, date of birth, place of birth, gender |
| Matriculation number | |
| Entry date | Password |
| Rights: ILIAS, Zoom | |
Digital identity: alice (the link) |
The link is what ties the two together: when the IdP confirms that alice has authenticated, the RP looks up its own record 1234 and applies the rights stored there. Authorisation therefore stays local to the RP, while authentication is delegated. A record may link to several identities, which is how "log in with Google or with Apple" for the same shop account works.