
Identity Provider
An identity provider is a service that verifies the identity of users and passes this proof on to other applications. Once a user logs in to the identity provider, they can access many different services without having to register anew everywhere.
An identity provider is a central service that answers a single question: Is this person really who they claim to be? The service checks a user’s credentials — for example, a password, fingerprint, or a code sent via SMS — and then issues a kind of digital ID. Other applications trust this ID and let the user in without performing their own separate check. This principle is familiar from everyday life as “Sign in with Google” or “Sign in with Apple” — Google and Apple act as the identity provider in these cases.
Why a centralized identity service makes sense
Without an identity provider, every app and every website would have to store and verify passwords on its own. That’s dangerous: if one of the many services suffers a data breach, millions of passwords are exposed. An identity provider consolidates this responsibility in one place that is specifically secured for this purpose.
For companies, this is even more important. A company with a thousand employees doesn’t want every piece of internal software maintaining its own user management system. When an employee leaves the company, it’s enough to disable their account at the identity provider — this immediately revokes their access to all connected systems at once. This saves time and closes security gaps.
How the ID is passed between services
The process follows a fixed pattern. Anyone wanting to sign in to an app is first redirected to the identity provider. There, they enter their credentials. After successful verification, the identity provider sends back a token — an encrypted, time-limited file that certifies the user’s identity. The app reads this token, trusts its contents, and grants access.
The token usually also contains additional information: what permissions the user has, which department they belong to, or when the session expires. Two widely used technical standards govern this process: OAuth 2.0 defines which app may access which data. OpenID Connect builds on top of this and additionally clarifies who the user is. Both standards ensure that services from different providers can communicate with one another without having to make their own individual arrangements.
It’s important to distinguish this from a related concept: authentication and authorization are two separate steps. The identity provider handles authentication — it verifies who someone is. What that someone is then allowed to do is often decided by the respective app itself. Some identity providers also take on this second step, but that is not a requirement.
Identity providers in products and headlines
The best-known identity providers for private users are Google, Apple, Meta, and Microsoft. Anyone who signs in to a news website using their Google account instead of creating a new password is using Google’s identity provider. In the enterprise world, services like Microsoft Entra ID (formerly Azure Active Directory), Okta, or Ping Identity are common. They manage sign-in for email, internal tools, video conferencing, and hundreds of other applications under a single login.
In tech news, the term frequently comes up in connection with security incidents. A compromised identity provider is especially dangerous: whoever controls it potentially gains access to all connected services at once. The 2023 attack on Okta made this clear — because Okta served as the identity provider for many large companies, the incident triggered a long chain of affected organizations.
The topic is also becoming more relevant in the field of AI applications. When an AI assistant accesses a calendar, emails, or company data on behalf of a user, it must prove that it is authorized to do so. For this, it uses the same token mechanism — and the company’s identity provider as the gatekeeper.