# Service Provider

A service provider (SP) is the application or service a user wants to access through [single sign-on (SSO)](https://clerk.com/glossary/single-sign-on-sso.md). It relies on an [identity provider (IdP)](https://clerk.com/glossary/identity-provider.md) to authenticate the user instead of collecting the user's credentials itself.

## How a service provider works

In a [SAML](https://clerk.com/glossary.md#security-assertion-markup-language-saml) sign-in flow, the SP can send the user to the IdP for authentication. After the user signs in, the IdP sends a SAML response to the SP's [Assertion Consumer Service (ACS)](https://clerk.com/glossary.md#assertion-consumer-service-acs) endpoint. The SP validates the response before creating a session for the user. The flow can also begin at the IdP.

For example, an employee might open a work application and be redirected to their organization's IdP. After authentication, the employee returns to the application. In this flow, the work application is the SP and the organization's sign-in service is the IdP.

**Service provider** is the term used for this role in SAML. In [OpenID Connect (OIDC)](https://clerk.com/glossary/openid-connect.md), the application that relies on authentication from an OpenID Provider is called a **relying party**.
