IDENTITY & TRUST CONNECTORS
Federation, Certificates & Trust
5 of 6Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.
OIDCSAML 2.0OAuth 2.xX.509mTLSOCSP / CRLeIDAS
Standards Based
Use established federation and PKI standards.
Strong Security
Validate tokens, certificates and secure channels.
Interoperable
Connect trusted national/EU identity ecosystems.
Governance Ready
Support audit, revocation and evolving trust frameworks.
Trust Architecture
1
External Trust
LuxTrust, Pro Santé Connect, eIDAS, national CAs and enterprise IdPs
2
Protocol Adapter
OIDC, SAML, OAuth, mTLS
3
Validation
Claims, signatures, chain, validity and policy
4
Revocation & Rotation
OCSP/CRL, key rotation and expiry monitoring
5
Mediloop Trust Context
Validated identity plus separate authorization
Protocols & Standards
| Standard | Use | Key consideration |
|---|---|---|
| OIDC / OAuth 2.x | Authentication and delegated authorization | Validate issuer, audience, nonce/state and scopes |
| SAML 2.0 | Enterprise federation | Metadata/signature validation |
| X.509 / mTLS | System and certificate trust | Chain, EKU, expiry and revocation |
| eIDAS / national eID | EU/national trust | Scheme-specific assurance and legal context |
Certificates & PKI
Use trusted certificate authorities and validated trust stores
Validate certificate chain, hostname/use and validity
Check revocation with OCSP/CRL when required
Monitor expiration well before production outage
Support overlapping rotation of keys/certificates
Protect private keys in secure secret/key management
Trust Frameworks
National Trust
Country-specific identity providers, healthcare PKI and registries.
European Trust
eIDAS and cross-border trust arrangements as applicable.
Healthcare Trust
Professional/organization verification and care-context requirements.
Mediloop Policy
Tenant, membership, scope, consent and purpose checks remain authoritative.
Implementation Guide
1
Discover
Provider metadata / certificate requirements
2
Configure
Client, redirect, cert and trust store
3
Validate
Tokens/assertions/certificates
4
Authorize
Map only trusted claims; apply Mediloop permissions
5
Operate
Monitor expiry, revocation and provider changes
APIs & Examples
typescriptCopy
// Conceptual verifier — provider-specific adapters stay behind this boundary
const trust = await identity.verifyExternalAssertion({
provider: 'national-idp',
assertion,
expectedTenantId,
});
if (!trust.verified) throw new Error('Untrusted identity');Illustrative SDK surface; public SDK names are not commitments until published.
Security & Compliance
Reject weak/invalid signature algorithms
Pin expected issuer/audience and provider metadata
Prevent replay and token substitution
Use short-lived credentials where possible
Log security-relevant trust decisions
Regularly test rotation/revocation paths
Developer Integration Surface
| Surface | Operation / resource | Use | Status |
|---|---|---|---|
| OIDC/SAML | authorize / callback / assertion validation | User federation | Standard |
| mTLS / X.509 | TLS client auth / certificate validation | System trust | Standard |
| OCSP / CRL | revocation status | Certificate lifecycle | PKI |
| Trust API | verify provider assertion / certificate | Mediloop connector abstraction | Planned/versioned |
Next Steps
Choose federation/trust mechanism
Register provider/client and trust anchors
Implement strict validation
Separate identity claims from authorization
Test expiry/revocation/rotation
Enable ongoing monitoring