Relying party (service provider)

The application that accepts an identity provider's assertion or token and grants access on its strength, instead of checking the user's credentials itself. SAML calls it the service provider.

A relying party (RP) is the system that relies on another party’s statement about a user’s identity, typically to grant access. NIST SP 800-63C-4 defines it in those terms and notes, in section 3.2.3, that some systems call it the service provider (SP). In federation the RP receives an assertion from the identity provider, verifies it, creates its own session for the user and grants access, without verifying the user’s authenticators itself. The name changes with the protocol: SAML says service provider, while OpenID Connect says relying party, which in OAuth terms is the OAuth client.

The RP’s security rests on validating what it receives: the assertion’s signature, issuer, intended audience and freshness. It still owns its authorisation decisions, and its own local account and session. That is why disabling a user at the identity provider may leave a session already open at the RP. It is the receiving side of federated identity. In public key infrastructure the same phrase names whoever relies on a certificate, a related but separate sense.

Exam relevance: a scenario is likely to ask which party authenticates the user in a federated sign-in and which consumes the result. Candidates are expected to place authentication at the identity provider and consumption at the RP, and to read relying party and service provider as one role.