<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 5, 2016 at 3:24 PM, Klingenstein, Nate <span dir="ltr"><<a href="mailto:nklingenstein@calstate.edu" target="_blank">nklingenstein@calstate.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id=":4ri" class="a3s aXjCH m157968542053aeb6">If you blur some of their requirements (e.g. uniqname:token rather than just a token -- why?) a vanilla SAML 2.0 artifact and a really simple webapp would suffice, no?<br></div></blockquote></div><br>Acting as a proxy between the IDP and the API Manager?</div><div class="gmail_extra"><br></div><div class="gmail_extra">Their flow diagrams suggest a proxy - but then why ask for the IDP to produce that output?</div><div class="gmail_extra"><br></div><div class="gmail_extra"><br></div></div>