What is the identity provider (IdP) responsible for, and which attributes does an IdP typically deliver?
The IdP issues and manages digital identities and, in a user-friendly way, issues, renews, replaces and revokes the subjects' authentication means; it guarantees confidentiality, integrity and availability of the credentials. Typical attributes are an identifier, e-mail, name and first name, and date of birth.
Its duties around authentication means:
- It creates, collects or assigns authentication features such as passwords or authentication certificates, or binds external authentication means to an identity using credentials.
- It keeps the credentials confidential, intact and available, which is why IdPs are prime targets for attackers: one breach exposes every subject's login.
Organisationally, an IdP usually has one or more registration authorities attached; IdP plus RA together are called an identity service. Standard attributes an IdP can assert about a subject are the identifier (for example the username), e-mail, name, first name and date of birth; richer attribute sets are a matter of what the IdP has verified.
Go deeper:
Identity provider (Wikipedia) โ IdP types and the protocols (SAML, OpenID Connect) they speak.