Map single sign-on between identity provider, service providers, and the user browser.
Free to start · Fully editable · Export to SVG, PNG, GIF & MP4
7 connected components you can rename, recolor, and extend with AI.
This diagram explains single sign-on architecture, where one set of credentials grants access to many applications. It shows the trust relationship between an identity provider and multiple service providers, with the user's browser relaying assertions or tokens. The building blocks include the IdP, the SAML or OIDC protocol exchange, the assertion or ID token, the user directory, and the downstream service providers that consume the authenticated session.
IT admins, identity engineers, and SaaS vendors use this SSO architecture diagram to design federated login, document SAML and OIDC integrations, and explain session flow to stakeholders. It is useful for enterprise onboarding, security reviews, and troubleshooting authentication issues across connected apps.
Single sign-on lets a user authenticate once with an identity provider and access multiple applications without logging in again. The IdP issues assertions or tokens that service providers trust.
SAML is an XML-based standard common in enterprise apps, while OIDC is a JSON and OAuth 2.0 based protocol popular for modern web and mobile apps. Both establish federated trust.
An identity provider, one or more service providers, the user browser, a user directory, and the protocol exchange that passes a SAML assertion or OIDC ID token.
It centralizes authentication, reduces password reuse, and lets organizations enforce MFA and policy in one place rather than across every individual app.
Visualize the OAuth 2.0 authorization code grant between client, server, and resource API
Show how zero trust enforces identity, device, and policy checks on every access request
Outline the incident response lifecycle from detection through recovery and lessons learned
Map assets, trust boundaries, and STRIDE threats across a system's data flows
Show how a SIEM ingests, correlates, and alerts on log data from across the environment
Break down how users inherit permissions through roles in a role-based access control model
Map independent services, an API gateway, databases and a message bus in a microservices system
Map API Gateway, Lambda functions, managed databases and event triggers in a serverless app
Open the sso architecture diagram (saml & oidc) in the Infogiph canvas, then edit, animate, and export.
Use this template