General guide for service operators

Switch edu-ID has more than 1 Million active users. Access to the university community with hundreds of thousands of students and staff

  • All Swiss universities are covered and already have contracts with Switch
  • Inter-university use
  • Easy entry for new users who do not yet have a Switch edu-ID account
  • Verified attributes
  • Access control based on supplied roles and attributes
  • Attributes verified by universities: e.g. student/employee status
  • Self-verified attributes: e.g. postal address, mobile number, ORCID
  • Service-specific attributes and their quality requirements
  • Password-free login with passkeys
  • Support for multi-factor authentication (MFA)
  • Duplicate checking
  • Can also be used by people who are not members of a university
  • Support for SAML and OIDC (OpenID Connect)
  • Can be used for authentication in web services and mobile apps
  • Efficient administration of your service with the Resource Registry

1. Contractual Preparation

Each application that is included in the federation must prove that it offers added value to Swiss universities and that it fulfills the technical and legal conditions of the Switch edu-ID federation.

A new application/service can be added to the federation if it is operated by a home organisation or a federation partner (common federation partner or federation partner plus).

If none of the above applies your organization must become a federation partner basic.

2. Protocol Choice: SAML vs OIDC

We provide a comparison table on our page SAML vs OIDC, so that you can choose accordingly which protocol is more adequate for your use case.

3. Identity Model Choice

Switch edu-ID offers a very comprehensive data model in different variants. Please check out the Identity and Attributes page and its subpages for further details.

  Description Configuration (SAML or OIDC)
Affiliation Identity Model

To access a service, a user chooses the home organization in the discovery service ("were are you from?"). The service receives an attribute assertion from the selected home organization. The assertion is compatible with traditional SWITCHaai assertions.

Only members of the selected home organization can authenticate and reach the service.

configure intended audience without personal identities
Personal Identity Model

To access a service, the user directly authenticates (without choosing a home organization). The service receives an attribute assertion of the user's private identity, independent of any organizational affiliation.
Optionally, the service can determine organizational roles and email addresses by evaluating swissEduIDLinked* attributes.

All users with an edu-ID account can authenticate to the service. Access restrictions have to be implemented in the service.

configure intended audience: personal identity
Extended Identity Model Like edu-ID only. Additional organizational affiliation attributes are fetched via affiliation API. Get additional attributes via affiliation API with read-only permissions.

4. Registration in the Resource Registry

Services are added to the edu-ID Federation by registering them in the Resource Registry https://rr.aai.switch.ch/

Any person, who is member of a university, of a Federation Partner or a Federation Partner Plus can register a service in the resource registry. To authenticate to the resource registry use your existing edu-ID account, or create an account on https://eduid.ch

The registration is fairly intuitive if you follow the wizard. Make sure the service description and contact data are complete.

During the registration of an application in the resource registry, the home organization (university) or federation partner on whose behalf the service is being registered must be specified. After completing the registration, you will automatically go through a confirmation process in which Switch and/or the responsible university will check your registration.

5. Advanced Service Configuration

Options to enhance the service quality, usability or security