This guide provides our partners with an overview and understanding of ID.me and the implementation of Security Assertion Markup Language (SAML).
ID.me is an Identity Verification Network providing a range of identity proofing for Federal, State and Local governments, organizations and commercial sector partners. ID.me is the only Credential Service Provider certified at NIST 800-63-2 LOA 1, 2, and 3, and NIST 800-63-3 IAL2/AAL2.
ID.me’s Identity Gateway platform provides a SAML 2.0 capable IdP service, which supports standardized, signed and encrypted assertions and different attribute bundles. This functionality can be used to enable applications to participate in a federated single sign-on (SSO) relationship with the ID.me network of credentials.
The ID.me SAML 2.0 IdP supports assertions, protocol bindings and profiles in accordance with the OASIS standard. The SAML XML document includes:
The following diagram shows an overview of the SAML flow. The “SP” in this diagram stands for “Service Provider”, a.k.a the partner.