# identity-provider

Source: https://startwithidentity.com/glossary/identity-provider/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A system that authenticates users and issues assertions or tokens vouching for their identity to other applications. In federated single sign-on, the identity provider (for example Okta, Microsoft Entra ID, or Ping) authenticates the user once and the relying service provider trusts its assertion, using [SAML](https://startwithidentity.com/standards/saml-2-0/) or [OpenID Connect](https://startwithidentity.com/standards/openid-connect/). Decentralized identity removes the runtime dependency on a central IdP by letting the holder present signed credentials directly.

Concentrating authentication in one provider is the right architecture and creates the obvious dependency: the IdP is now both the highest-value target and a single point of failure. That is why break-glass paths, IdP-side threat detection, and a tested answer to "what do we do when the IdP is down or compromised" belong in the design rather than in the incident retrospective.

See also: [SSO](https://startwithidentity.com/glossary/sso/), [federation](https://startwithidentity.com/glossary/federation/), [service provider](https://startwithidentity.com/glossary/service-provider/), [Okta 2023 support system breach](https://startwithidentity.com/breaches/okta-2023-support-system-breach/)
