Back to Blog // protocols

SAML vs OIDC vs SCIM: Choosing the Right Protocol

SAML, OIDC, and SCIM solve different problems. This is a plain-language guide to what each one does and when to reach for it in a federated deployment.

December 10, 2024 · Veripass
SAML vs OIDC vs SCIM: Choosing the Right Protocol

These three acronyms get listed together so often that they start to feel interchangeable. They are not. SAML and OIDC answer “is this user authenticated?” SCIM answers “does this user account exist and is it current?” Choosing well means knowing which question you are actually asking.

OIDC: modern authentication

OpenID Connect is an identity layer built on top of OAuth 2.0. It is the protocol you reach for when you want a clean, token-based authentication flow, especially for web and mobile applications and for federating with modern directories.

Veripass federates with Microsoft Entra ID and Google Workspace over OIDC. A user authenticates against their home directory, the provider issues a token, and Veripass consumes it to establish a session. OIDC is JSON- and JWT-based, which makes it a natural fit for APIs and contemporary application stacks.

Reach for OIDC when:

  • You are integrating with Microsoft Entra ID or Google Workspace.
  • You want token-based sessions that travel well across web and API surfaces.
  • You are building or modernizing rather than maintaining a legacy SAML estate.

SAML: the enterprise standard

SAML predates OIDC and remains deeply entrenched in enterprise identity. It is XML-based and assertion-driven, and a great deal of existing enterprise software still speaks it natively. If an organization’s stack is built around SAML, federating over SAML is often the path of least resistance.

Veripass supports SAML for inbound authentication, so an organization that already runs a SAML identity provider can federate without re-platforming. Functionally, SAML and OIDC overlap heavily — both establish authenticated identity through a trusted assertion. The difference is mostly one of ecosystem and era.

Reach for SAML when:

  • Your existing identity provider or applications speak SAML natively.
  • You need to integrate with enterprise systems that have not moved to OIDC.

SCIM: lifecycle, not login

This is the one that is genuinely different. SCIM — System for Cross-domain Identity Management — is not about authentication at all. It is about provisioning. SCIM keeps account state synchronized: it creates users, updates their attributes, and deprovisions them when they leave.

Authentication tells you a user is who they say they are right now. It does nothing about the account that was never created, or the one that should have been disabled last week. That gap is exactly what SCIM closes. In Veripass, SCIM provisioning means accounts flow from the upstream directory automatically — including deprovisioning, so offboarding in the home directory removes access without a manual sweep.

Reach for SCIM when:

  • You want account creation and removal to follow the directory automatically.
  • Deprovisioning has to be reliable for security or compliance reasons.

They are not competitors

The framing “SAML vs OIDC vs SCIM” is a little misleading, because SCIM is not competing with the other two — it complements them. A typical Veripass deployment uses one of SAML or OIDC for authentication and SCIM for lifecycle, side by side.

  • Authentication: pick OIDC for modern stacks and Entra/Google federation; pick SAML when the ecosystem demands it.
  • Provisioning: use SCIM regardless of which authentication protocol you chose.
  • Machine identities: for service-to-service traffic, neither applies — use API keys.

Get the pairing right and you have authenticated identity that is also continuously in sync, with every action landing in the audit trail. Choose by the question you are asking, not by the acronym that sounds closest.

Keep reading

Architecture Overview: Federating Identities at Scale

Architecture Overview: Federating Identities at Scale

How Veripass federates identities across many applications and organizations from a single multi-tenant control plane, without forcing every team onto one directory.

Audit Trails That Survive an Audit

Audit Trails That Survive an Audit

An audit trail is only useful if it holds up when someone actually audits it. Here is what makes Veripass audit records immutable, attributable, and reconstructable.

Hybrid and On-Premise Identity Without Lock-In

Hybrid and On-Premise Identity Without Lock-In

Not every workload belongs in the cloud. Here is how Veripass runs the same federation, policy, and audit model across cloud, on-premise, and hybrid deployments.