Skip to main content

SAML vs OIDC

Anna Davidson avatar
Written by Anna Davidson
Updated this week

When connecting Ben to your organisation’s systems, choosing the right authentication method is crucial. Ben supports two main protocols for single sign-on: OpenID Connect (OIDC) and Security Assertion Markup Language (SAML).

What Are OIDC and SAML?

OIDC and SAML are both protocols used to facilitate single sign-on, allowing users to log in to multiple systems using a single set of credentials. Despite their shared purpose, they operate differently and are better suited to different needs.

  • OIDC: A modern authentication protocol built on top of the OAuth 2.0 framework. It’s lightweight and designed to be easily consumed by mobile and web applications.

  • SAML: An older, more established protocol designed primarily for enterprise-level applications and desktop environments. It’s more customisable, allowing for a wide range of configuration options and compatibility with legacy applications.

Why Ben Recommends OIDC

At Ben, we’ve made it easy for customers to start using OIDC with Google and Microsoft preconfigured. This allows for a quick and seamless setup, making it an ideal choice for most customers.

Here’s why OIDC might be the better option for you:

  1. Ease of Setup: OIDC is simpler to configure, especially in Google and Microsoft. This reduces the time and technical overhead needed to get started with Ben.

  2. Modern Protocol: OIDC was specifically designed with modern web and mobile applications in mind, meaning it works across lots of different devices and platforms with a consistent user experience. This includes the Ben web app and the mobile app!

  3. Scalability: OIDC’s lightweight architecture ensures efficient performance as your user base grows, making it easy to scale from small teams to large enterprises.

When to Consider SAML

While OIDC is generally easier to implement, there are scenarios where SAML might be more appropriate:

  1. A Different Identity Provider: If your organisation uses another identity provider (IdP) than Google or Microsoft, SAML may be the better choice, as Ben’s OIDC is currently pre-configured solely for these two providers.

  2. Advanced Security Requirements: SAML offers more complex configurations and can be better suited for organisations with more specific security policies or regulatory requirements.

  3. Established Systems: If your organisation relies on legacy or enterprise-grade systems that already use SAML, using SAML with Ben can simplify the process by maintaining consistency with your existing infrastructure.

Conclusion

For most customers using Google or Microsoft, OIDC offers a faster, simpler path to integrating Ben. However, if your organisation has specific needs or existing infrastructure that relies on SAML, you can still configure Ben to work seamlessly with it.

If you’re unsure which protocol to use, or if you need help with the setup process, our support team is here to assist you.

Did this answer your question?