Concepts¶
Identity systems are mostly vocabulary. The mechanisms underneath are not complicated, but almost every word — scope, claim, audience, grant — means something narrower than it sounds. These pages introduce them in the order that makes each one make sense.
Read them in order the first time.
- Identity and access — the five nouns the whole system is built from, and how a person ends up with permissions.
- Tokens — what IDEN hands out, what each kind is for, and why applications must never confuse them.
- Sessions and single sign-on — how one sign-in becomes access to every application, and how signing out reaches all of them.
- Assurance and step-up — how strongly someone proved who they are, and how an application demands more.
- Consent — what an application is allowed to ask for on someone's behalf.
- Profile fields — how an organization defines what it collects about people.
- The audit log — what is recorded, and what that record is for.
The shortest possible summary¶
A person signs in and gets a session. An application sends them to IDEN and receives a token. That token carries permissions, which the person holds because an administrator gave them — directly, or through a role, or through a group. Your own API reads the token and decides what to allow.
Everything else is detail about how each of those is proved, limited, revoked, and recorded.