# service-provider

Source: https://startwithidentity.com/glossary/service-provider/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

The application that consumes identity assertions from an IdP to grant the user access. In SAML it's the SP; in OIDC the equivalent is the Relying Party.

The service provider does the validation, and therefore owns most of the risk in a federation. Checking the signature is necessary and not sufficient: the assertion must be for this SP, recent, unreplayed, and from the expected issuer with an algorithm you chose rather than one the message declared. A long run of SAML bypasses come from skipping one of those.

See also: [identity provider](https://startwithidentity.com/glossary/identity-provider/), [relying party](https://startwithidentity.com/glossary/relying-party/), [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/), [federation](https://startwithidentity.com/glossary/federation/)
