<div dir="ltr">We're in process of replacing our combination of the Shibboleth IDP and our legacy SSO to strictly Shibboleth.<div><br></div><div>One concern raised by our campus is that our legacy SSO provided the ability for SPs to self provision (as long as your host met certain criteria, you could just point the SP at Cosign and it would work).</div><div><br></div><div>I would really not rather loosen the restrictions on the UnverifiedRelyingParty and run an open IDP.</div><div><br></div><div>What we've been asked for are APIs that would allow end systems (like container orchestrators) to programmatically provision SPs on the fly.</div><div><br></div><div>It seems like some of this might be doable using the metadata managed configuration... but there's still the issue of getting the metadata onto the IDP.<br></div><div><br></div><div><div style="font-size:small;text-decoration-style:initial;text-decoration-color:initial">Has anyone implemented something similar?</div><br></div><div>Liam</div></div>