SP initiation, MFA handoff, ACS validation, assertion checks, claims, role mapping, logout, readiness, and failure evidence.
One operating model without pretending the protocols are the same.
FreeSCIM keeps the trust mechanics honest while giving operators a common view of readiness, decisions, sessions, failures, and response.
Discovery, JWKS validation, authorization-code flow, state, nonce, PKCE, scopes, group claims, role mapping, and sessions.
Application registration, client and key governance, readiness, and controlled broker components exist without being presented as the institutional production identity provider.
Provider catalog, maturity state, onboarding completeness, protocol health, key freshness, session state, drift, replay evidence, stewardship, and diagnostics.
The trust path is inspectable before it is trusted.
Issuer, redirect URI, discovery, keys, state, nonce, PKCE, scopes, claims, role strategy, and session behavior are explicit parts of readiness rather than hidden implementation details.
- OIDC discovery and JWKS are readiness dependencies.
- State, nonce, PKCE, scopes, and claims remain explicit controls.
- SAML and OIDC failures retain correlation without leaking assertions or tokens.
- OIDC can remain disabled or scope-limited while its readiness and security controls are evaluated.
Authentication events join the operational story without sharing credentials.
SCIM bearer provisioning, browser SSO, provider intelligence, and federation sessions remain separate channels. Their evidence can still be correlated safely.
Authentication starts
Initiation, callback, MFA handoff, redirect, and protocol readiness are visible as their own lifecycle.
Role decisions
Claims, groups, policy, and application role mapping stay inspectable without flattening provider semantics.
Session governance
Session establishment, logout, trust state, and suspicious patterns contribute to the same operator evidence model.
Failure intelligence
Protocol failures retain request and correlation context while protecting cookies, tokens, assertions, secrets, and private keys.
Framework presence is not the same as a live federation relationship.
The runtime explicitly tracks provider maturity so a declared template cannot be mistaken for configured, authenticated, write-capable, or production-proven integration.
Move a provider through maturity without pretending declaration means integration.
The preview mirrors the runtime's federation operations vocabulary: application runtime, trust, drift, onboarding, replay, launch readiness, and provider maturity.
Trust is a path, not a checkbox.
Successful and failed starts, callbacks, role decisions, sessions, logout, protocol health, and suspicious patterns remain available to operators as evidence.