Affiliation identities now available on OIDC

We’re happy to announce a new capability for services relying on OpenID Connect (OIDC): affiliation identities are now supported.

What’s new

Until now, retrieving a user’s complete affiliation data (including e.g. local attributes) directly, and using a well-known/standard protocol was only possible through SAML. With this update, services using OIDC can also request and receive the same affiliation information straight away.

In short, OIDC catches up with SAML on this front: it’s no longer necessary to choose SAML over OIDC just to get access to affiliation data. Both protocols now offer equivalent functionality here.

Example of the identity chooser user interface with two affiliations and the personal identity

What this means for you

If you’re already running a service (on OIDC or SAML) nothing changes. This update doesn’t require any action on your part, and existing integrations will continue to work exactly as they do today.

If you’re using OIDC, you gain a new option: services can now define their audience based on affiliation, using a more precise way to control who can access your service.

If you’re using SAML, missing support of the Affiliation identity model doesn’t block you anymore from migrating to OIDC.

Learn more

For technical details on how to configure affiliation-based audiences in your OIDC integration, check out our documentation: https://help.switch.ch/eduid/service/oidc/identityselection/

Leave a Reply

Discover more from SWITCH Identity Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading