Identity Provider (IdP)
The party in a federation that authenticates the user and issues a signed assertion or token about them to relying parties; called the OpenID Provider (OP) in OpenID Connect.
An identity provider (IdP) is the system that authenticates a user and then vouches for that user to other services. NIST SP 800-63-4 defines it as the party in a federation transaction that creates an assertion for the subscriber and sends it to the relying party. In SAML the IdP (the asserting party) issues a signed SAML assertion to a service provider. In OpenID Connect the same role is named the OpenID Provider (OP), and its assertion is the ID token.
The IdP is where federated identity and cross-domain single sign-on concentrate their trust. Relying parties accept its signed statements instead of checking passwords themselves, so the IdP’s authentication strength, its sessions and its signing keys carry the weight for the connected applications. A stolen signing key lets an attacker mint assertions for that provider’s users, the pattern commonly called Golden SAML. Disabling a user at the IdP stops new sign-ins, but sessions and accounts already created at each relying party end only when those are ended too.
Exam relevance: a scenario is likely to ask which party authenticates the user in a federated login. Candidates are expected to answer the identity provider, not the service provider or relying party, and to recognise the IdP and its signing key as a point of concentrated risk.