Search code examples
single-sign-on

Can SAML response contain custom data?


We have multiple websites that share the same customer base but doing different kind of business. We already have a server that acts as a centralized identity service - it manages customers, their businesses and customer's roles in the businesses.

Because of the existence of this centralized identity service, we decide to add single-sign-on to this service - i.e. to make it act as a SSO identity provider.

A customer may have roles in multiple businesses - he could be an admin in business A and a technician in business B. When he logs in, our centralized identity service makes him to pick a business to login.

Question: does SAML response contain fields/attributes to carry this information: "The user has logged into business B as a technician"?


Solution

  • This document answers the question I asked:

    http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html