Also why is it sometimes called a federated ID? Does it have to be an email address or could any value work?

  • eerongalA
    link
    fedilink
    English
    arrow-up
    9
    ·
    9 months ago

    SSO is basically offloading your authentication to a trusted third party. Instead of having the user set up an account with a password in your system, you instead go “hey Google/Microsoft/okta/whatever, do you know this guy?”.

    In theory it doesn’t have to be an email address, just any sort of account with said third party, email is just usually the standard to go with.