- 12.10.1. Using Transient Federation Identifiers
- 12.10.2. Using Persistent Federation Identifiers
- 12.10.3. Changing Federation of Persistently Linked Accounts
- 12.10.4. Terminating Federation of Persistently Linked Accounts
- 12.10.5. Configuring Auto-Federation
- 12.10.6. Linking Federated Accounts in Bulk
Identity providers and service providers must be able to communicate about users. Yet in some cases the identity provider can choose to communicate a minimum of information about an authenticated user, with no user account maintained on the service provider side. In other cases the identity provider and service provider can choose to link user accounts in a persistent way, in a more permanent way, or even in automatic fashion by using some shared value in the user's profiles such as an email address or by dynamically creating accounts on the service provider when necessary. OpenAM supports all these alternatives.

