Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

InAcademia is available as a SAML 2.0 Service Provider (SP) for eduID.at Identity Providers that also participate in Interfederation/eduGAIN. (All eduID.at IDPs should participate in Interfederation/eduGAIN.)
It also acts as an OpenID Connect Provider (OP) for any connected student discount platforms (or "merchants"), providing for easier integration of the student verification flow within mobile apps, for example.

Due to its setup as a proxy InAcademia can also act as a "data firewall": First it only requests the minimum data to be released from IDPs. Then it also filters down any data recieved from the IDP (requested or not) to the abolute minimum before providing the basic piece(s) of information to the merchant: Whether the subject is a student (or an employee) of the institution or not. Depending on the "flow"/integration chosen by the merchant an opaque identifier for the subject may also be shared with the merchant, to support use cases that require the subject to be recognised across visits. But even the opaque identifier (if chosen) is dynamically generated and pseudonymised by InAcademia, based on data recieved from the SAML IDP.

...