Hacker News new | ask | show | jobs
by actualanswer 3111 days ago
SAML IdP is the entity that stores the identities (source of truth), SSO provider can be the same IdP or a 3rd party entity that can federate this identity to different service providers (apps).
2 comments

Yeah, I don't care about these terms at all. I'm happy to get directory integration working, or to proxy SAML from elsewhere (as long as it conforms to the minimal SAML I'm willing to speak).
You should care about these terms while building and marketing software in the space. I'm not saying you're being deceitful, however, almost anyone who read your description assumed your offering to have feature parity with AWS SSO, but the feature list probably is closer to AWS Cognito. An open alternative to Cognito might be sufficient for most, but is still not the same as a comprehensive SSO manger
I think we're just going to put it on Github for now and say "here's this thing and here's what it can do" and not worry too much about an Eric and Al Ries-approved Positioning marketing strategy. Not giving a shit about stuff is pretty liberating. :)
It doesn't have to store the entities; it's just trusted by some set of service providers to provide identity claims. Nothing in the definition says an IdP can't federate further.