ποΈ Entities & Roles
The hierarchy of players in a federation
The Hierarchy β Click Any Node
Every federation is organized as a hierarchy.[1] At the top sits the Trust Anchor, which may delegate authority to Intermediate Entities, who in turn manage Leaf Entities β the OpenID Providers, Relying Parties, and other services that participate in the federation.
Multi-Federation Membership
An entity MAY have multiple Entity Types[2] and can be a member of multiple federations simultaneously. For example, a university identity provider might participate in both a national education federation and a research consortium federation, each with its own Trust Anchor.
Entity Types at a Glance
Trust Anchor
Intermediate Entity
OpenID Provider
Relying Party
OAuth Authorization Server
Resource Server
OAuth Client
Federation Entity
Real-World Analogy
Think of a government structure: the national government (Trust Anchor) sets the rules, state or regional agencies (Intermediates) enforce those rules locally, and citizens and businesses (Leaf Entities) operate under them. Each level can add its own requirements, but never weaken the level above.