Parallel protocols

One operating model without pretending the protocols are the same.

FreeSCIM keeps the trust mechanics honest while giving operators a common view of readiness, decisions, sessions, failures, and response.

SAML service provider

SP initiation, MFA handoff, ACS validation, assertion checks, claims, role mapping, logout, readiness, and failure evidence.

OIDC relying party

Discovery, JWKS validation, authorization-code flow, state, nonce, PKCE, scopes, group claims, role mapping, and sessions.

OIDC broker governance

Application registration, client and key governance, readiness, and controlled broker components exist without being presented as the institutional production identity provider.

Federation operations

Provider catalog, maturity state, onboarding completeness, protocol health, key freshness, session state, drift, replay evidence, stewardship, and diagnostics.

Federation trust-path architecture
Security controls

The trust path is inspectable before it is trusted.

Issuer, redirect URI, discovery, keys, state, nonce, PKCE, scopes, claims, role strategy, and session behavior are explicit parts of readiness rather than hidden implementation details.

  • OIDC discovery and JWKS are readiness dependencies.
  • State, nonce, PKCE, scopes, and claims remain explicit controls.
  • SAML and OIDC failures retain correlation without leaking assertions or tokens.
  • OIDC can remain disabled or scope-limited while its readiness and security controls are evaluated.
Shared evidence

Authentication events join the operational story without sharing credentials.

SCIM bearer provisioning, browser SSO, provider intelligence, and federation sessions remain separate channels. Their evidence can still be correlated safely.

SSO

Authentication starts

Initiation, callback, MFA handoff, redirect, and protocol readiness are visible as their own lifecycle.

MAP

Role decisions

Claims, groups, policy, and application role mapping stay inspectable without flattening provider semantics.

SES

Session governance

Session establishment, logout, trust state, and suspicious patterns contribute to the same operator evidence model.

ERR

Failure intelligence

Protocol failures retain request and correlation context while protecting cookies, tokens, assertions, secrets, and private keys.

Provider maturity

Framework presence is not the same as a live federation relationship.

The runtime explicitly tracks provider maturity so a declared template cannot be mistaken for configured, authenticated, write-capable, or production-proven integration.

01DeclaredThe provider or application pattern exists in the registry or template catalog.
02ConfiguredTenant-specific issuer, client, metadata, redirect, or target settings are present.
03ReachableThe external trust endpoint can be contacted and inspected.
04AuthenticatedThe trust exchange succeeds with the intended credentials and protocol.
05ProvenEnvironment-specific user flow, failure behavior, governance, and recovery have direct evidence.
Federation console preview

Move a provider through maturity without pretending declaration means integration.

The preview mirrors the runtime's federation operations vocabulary: application runtime, trust, drift, onboarding, replay, launch readiness, and provider maturity.

Federation is observable

Trust is a path, not a checkbox.

Successful and failed starts, callbacks, role decisions, sessions, logout, protocol health, and suspicious patterns remain available to operators as evidence.