What does the relying party do in an IAM system, what does it need at runtime, and under which other names does it appear?
The relying party is the application that represents the resource's interests: it uses IAM services, defines the access rules for its resources, and at runtime needs the subject's digital identity with the authorisation-relevant attributes plus the context of the access. Synonyms include service provider (SAML SP), verifier and information consumer.
The RP is the consumer side of IAM:
- It uses IAM services, processing information from IAM providers to protect its resources.
- It defines the access rules: which subjects may access which resources under which conditions.
- To decide at runtime it needs more than a yes from the login: the digital identity with the attributes that matter for authorisation (role, department, age) and the context of the access (location, time, trust level of the authentication).
The list of synonyms is long because every standard names it differently: Informationsbezüger, information consumer, identity consumer, solution provider, SAML Service Provider (SP), verifier (in the SSI world), relying party. Recognising them as one role saves confusion when reading protocol specifications.
Go deeper:
Relying party (Wikipedia) — the term as used in web authentication protocols.