An open standard for exchanging authentication and authorization data between parties, especially between an identity provider and a service provider.