# Decentralized Identity vs Federated Identity

Source: https://startwithidentity.com/guides/decentralized-identity/decentralized-identity-vs-federated-identity/
Last updated: 2026-07-06
License: content by Start with Identity. Cite the source URL.

---

Federated identity and decentralized identity both answer "how does a service know who you are," but they do it in opposite ways. Understanding the difference helps you place each correctly rather than treating decentralized identity as a replacement for what you already run. For the primers, see [what is decentralized identity](https://startwithidentity.com/guides/fundamentals/what-is-decentralized-identity/) and [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/).

## The two models

**Federated identity** puts a central [identity provider](https://startwithidentity.com/glossary/identity-provider/) in the middle. At login, the IdP authenticates you and sends the service an assertion vouching for you, using [SAML](https://startwithidentity.com/standards/saml-2-0/) or [OpenID Connect](https://startwithidentity.com/standards/openid-connect/). The service trusts the IdP in real time.

**Decentralized identity** removes the runtime middleman. An [issuer](https://startwithidentity.com/glossary/issuer-holder-verifier/) signs a [verifiable credential](https://startwithidentity.com/standards/verifiable-credentials/) and gives it to you. You hold it in a [wallet](https://startwithidentity.com/glossary/digital-wallet/) and present it directly to a verifier, which checks the signature and issuer without calling anyone. See the full picture in [decentralized identity explained](https://startwithidentity.com/guides/decentralized-identity/decentralized-identity-explained/).

## How they compare

- **Trust model:** federated trusts a live provider; decentralized trusts a signature and the issuer's key.
- **Availability:** federated depends on the IdP being up at login; decentralized credentials can be verified offline.
- **Privacy:** in federation the IdP can see every login; decentralized presentation reveals nothing to the issuer at verification time, and [selective disclosure](https://startwithidentity.com/glossary/selective-disclosure/) shares only what is needed.
- **Portability:** federated identities live in a provider's namespace; decentralized credentials are portable and holder-controlled.
- **Maturity:** federated is battle-tested and universal; decentralized is younger, with wallet adoption still spreading.
- **Single point of failure:** the IdP is one in federation; decentralized removes it but shifts responsibility to holders for key and wallet management.

## Where each wins

**Federated identity wins** for workforce single sign-on, app-to-app authentication, and anywhere a mature, universally supported protocol and central control are what you want. It is not going away.

**Decentralized identity wins** for reusable [identity verification and KYC](https://startwithidentity.com/guides/decentralized-identity/reusable-identity-and-kyc-with-verifiable-credentials/), portable credentials like certifications that should outlast any provider, privacy-sensitive proofs (age, eligibility), and government or cross-border identity such as the [EUDI Wallet](https://startwithidentity.com/standards/eidas-2-eudi-wallet/) and [mDL](https://startwithidentity.com/standards/iso-18013-5-mdl/).

## The future is hybrid

These models are not a war with a winner. The realistic architecture for most organizations is both: keep [federated SSO](https://startwithidentity.com/standards/openid-connect/) for sign-in, add decentralized credentials for reusable and portable proofs, and bridge them with an [identity fabric](https://startwithidentity.com/guides/fundamentals/what-is-identity-fabric/). Standards are converging to make this practical, notably [OpenID4VC](https://startwithidentity.com/standards/openid4vc/), which builds decentralized credential exchange on the same OAuth foundation federated identity already uses.

## Where to go next

Overview: [decentralized identity explained](https://startwithidentity.com/guides/decentralized-identity/decentralized-identity-explained/). Build: [verifiable credentials implementation guide](https://startwithidentity.com/guides/decentralized-identity/verifiable-credentials-implementation-guide/). Standards: [Verifiable Credentials](https://startwithidentity.com/standards/verifiable-credentials/), [DID](https://startwithidentity.com/standards/decentralized-identifiers-did/).
