# Identity Provider

An identity provider (IdP) is a service that authenticates a user and supplies identity information to an application the user wants to access. An organization can connect its IdP to multiple applications so it can manage sign-in centrally. Examples of IdPs include Okta, Microsoft Entra ID, and Google Workspace.

## How an identity provider works

In a [SAML](https://clerk.com/glossary.md#security-assertion-markup-language-saml) sign-in flow, the IdP authenticates the user and sends an assertion to the [service provider (SP)](https://clerk.com/glossary/service-provider.md). The SP validates that assertion before granting access. Sign-in can begin at either the application or the IdP.

In [OpenID Connect (OIDC)](https://clerk.com/glossary/openid-connect.md), the corresponding role is the **OpenID Provider**. An OpenID Provider is an OAuth 2.0 authorization server that authenticates the user and provides identity claims to the application, called a **relying party**, through an ID token.
