# relying-party

Source: https://startwithidentity.com/glossary/relying-party/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

The application that relies on an external identity provider to authenticate users. The term is used in OIDC and WebAuthn. The RP validates tokens or assertions but does not store user credentials itself.

Being a relying party means outsourcing authentication and keeping responsibility for validation, which is where the bugs live: accepting an assertion without checking the audience, trusting a signature algorithm the attacker chose, or treating an ID token as an API credential. In WebAuthn the RP identifier is also the security boundary, since it determines which origin a credential will sign for.

See also: [identity provider](https://startwithidentity.com/glossary/identity-provider/), [OpenID Connect](https://startwithidentity.com/standards/openid-connect/), [WebAuthn and FIDO2](https://startwithidentity.com/standards/webauthn-fido2/), [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/)
