---
title: "STACKIT Identity Provider"
description: "Central platform identity management delivering SSO, SAML/OIDC enterprise federation, SCIM provisioning, and WIF service accounts."
scfAsset:
  category: "service"
  managed: false
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Identity", "IdP", "SSO", "OIDC", "SCIM", "Authentication"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-idp/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-idp.mdx"
---

STACKIT IdP handles central authentication across the platform, bridging enterprise identity systems with STACKIT services.

## Service Overview
- **Centralized Single Sign-On**: Seamlessly federates with corporate identity providers like Entra ID and Google Workspace.
- **Automated Lifecycle**: Automated user onboarding and offboarding via SCIMv2 integration.
- **Keyless Automation**: Workload Identity Federation (WIF) eliminates static, long-lived API keys.

## Technical Details
- **Protocols**: Supports SAML 2.0, OIDC 1.0, and SCIMv2 (RFC 7642).
- **Service Accounts**: Authenticated using RSA signed JWTs (Key Flow) or short-lived OIDC assertions (WIF).

## Limitations & Constraints
- **Platform Scope Only**: Provides identity management exclusively for STACKIT platform access, not for custom tenant applications.
- **Federation Setup**: Initial enterprise IdP federation configurations require support ticket requests.

<LinkCard title="STACKIT IdP Documentation" href="https://docs.stackit.cloud" />
