Hacker News new | past | comments | ask | show | jobs | submit login

This is actually something I hadn’t really considered before. Writing an IdP is in many ways probably much easier than writing a service provider because there are many fewer knobs you need to turn. Not none, but fewer. You probably have one template for assertions that contains all the clauses and conditions you care about and you set them all every time.

Clients can be much harder because you can any number of combinations of instructions thrown your way and you have to respect their intent. This is much harder to deal with.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
