Single-Sign-On

Notes on general principles regarding authentication via Single Sign On

Important Terminology

Available Protocols

Authentication Flows

With most SSO configurations you can allow for users to authenticate directly from the SP, redirecting you to the IDP for authentication and back to the SP (Service-provider-initiated auth), or from the IDP directly into the Service (Identity-provider-initiated auth). These are two different means to the same end.

Some examples of places with further documentation on this point:

IDP Initiated Authentication

SP Initiated Authentication

Common SSO Design Patterns

References