---
title: "Identity Provider — Identity Glossary | IDSync"
description: "An Identity Provider (IdP) is the system that authenticates users (or workloads) and issues signed assertions about their identity to other applications…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Identity Provider",
          "item": "https://idsync.com/glossary/identity-provider"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/identity-provider",
      "name": "Identity Provider",
      "alternateName": [
        "IdP",
        "IdP",
        "Identity Provider",
        "OP (OpenID Provider)"
      ],
      "description": "An Identity Provider (IdP) is the system that authenticates users (or workloads) and issues signed assertions about their identity to other applications — Okta, Microsoft Entra ID, Google Workspace, Auth0, Ping Identity, and Keycloak are common examples.",
      "url": "https://idsync.com/glossary/identity-provider",
      "inDefinedTermSet": "https://idsync.com/glossary"
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Identity Provider 

Architecture

# Identity Provider (IdP)

An Identity Provider (IdP) is the system that authenticates users (or workloads) and issues signed assertions about their identity to other applications — Okta, Microsoft Entra ID, Google Workspace, Auth0, Ping Identity, and Keycloak are common examples.

Last reviewed 3 months ago

Key points

-   The IdP holds the authoritative user record and credentials (or delegates to social/enterprise IdPs).
-   In SAML, the IdP issues signed Assertions to Service Providers. In OIDC, the OpenID Provider (OP) issues ID tokens to Relying Parties.
-   Workforce IdPs: Okta, Microsoft Entra ID, Google Workspace, Ping, JumpCloud. CIAM IdPs: Auth0, Cognito, Keycloak, FusionAuth, Stytch.
-   An IdP is the chokepoint for MFA, conditional access, lifecycle (SCIM), and audit — making it the single most important system in your security stack.
-   Federated IdPs let you accept identities from external orgs (B2B SSO) or social networks (consumer login).

## What is an Identity Provider?

An **Identity Provider (IdP)** is the system of record for _who_ a user (or workload) is, and the authority that signs cryptographic assertions telling other applications "yes, this is alice@acme.com, here's what we know about her."

In the SSO world, the IdP authenticates the user once, then issues short-lived tokens that downstream applications — called **Service Providers (SPs)** in SAML or **Relying Parties (RPs)** in OIDC — accept as proof of identity.

## What the IdP owns

-   **Credentials and authenticators** — passwords (ideally none), passkeys, FIDO2 keys, TOTP, push, biometrics.
-   **The authentication policy** — MFA rules, conditional access, device trust, risk-based step-up.
-   **The user directory** — either native (Entra ID, Google Workspace) or synced from an HRIS / on-prem AD.
-   **Federation trust** — relationships with downstream SPs (via SAML metadata or OIDC client registration) and upstream IdPs (social, B2B).
-   **Audit and logs** — every sign-in, every consent grant, every admin change.

## Workforce vs CIAM IdPs

| Workforce IdP | CIAM IdP | | --- | --- | | Okta, Entra ID, Google Workspace, Ping, JumpCloud | Auth0, Cognito, Keycloak, FusionAuth, Stytch, WorkOS, Frontegg | | Optimized for employees: SCIM, lifecycle, MFA enforcement | Optimized for customers: progressive profiling, social login, multi-tenant, B2B SSO | | ~$3–15 per user/month | Pricing by MAU | | HRIS-driven JML | Self-service signup, account recovery, consent management |

## When buyers care

Picking the IdP is the single biggest identity decision a company makes:

-   **Cost of switching is enormous** — every downstream SP integration has to be re-federated.
-   **Security depends on it** — IdP compromise = total compromise (Okta breaches, midnight blizzard).
-   **It defines your MFA story, lifecycle automation ceiling, and B2B SSO capabilities.**

## Editorial note

When evaluating an IdP, score on these, in order: (1) phishing-resistant MFA support and policy granularity, (2) lifecycle (SCIM in/out and HRIS-driven), (3) admin model (delegated admin, just-in-time elevation, MFA on admins), (4) audit & logs (export to SIEM, retention), (5) breach history and customer-facing incident response.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[iam platforms](/directory/category/iam-platforms)[ciam](/directory/category/ciam)

### Related terms

[sso](/glossary/sso)[saml](/glossary/saml)[openid connect](/glossary/openid-connect)[service provider](/glossary/service-provider)[scim](/glossary/scim)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the iam platforms category.

[Explore tools](/directory/category/iam-platforms)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.