In this wiki the common therm for a Verifier is a Relying Party. The distinction seems to be moot.


New standards like to talk about the Verifier rather than the Relying Party for reasons known only to them.


  • The term Verifier could be limited to just the role played by any Entity in assuring that the data received meets its own criteria for acceptance.
  • Some verticals, like finance and health, are highly regulated and typically require that their data controllers are certified for conformance with very restrictive regulations. Others have lighter regulation like the US Federal Trade commission.
  • In all cases the verifier will be given a set of policies that they apply to Claimants seeking access. In a world where policies can change will little notice, it behooves the Verifier to create a Policy-Based Access Control applications that does not require reprogramming of the application to meet changing policies.


For this wiki we break the Verifier into two roles from SAML:

  1. PDP = policy definition point
  2. PEP = policy enforcement point