Mediloop
IDENTITY & TRUST CONNECTORS

Federation, Certificates & Trust

5 of 6

Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.

OIDCSAML 2.0OAuth 2.xX.509mTLSOCSP / CRLeIDAS
Standards Based

Use established federation and PKI standards.

Strong Security

Validate tokens, certificates and secure channels.

Interoperable

Connect trusted national/EU identity ecosystems.

Governance Ready

Support audit, revocation and evolving trust frameworks.

Trust Architecture
1
External Trust
LuxTrust, Pro Santé Connect, eIDAS, national CAs and enterprise IdPs
2
Protocol Adapter
OIDC, SAML, OAuth, mTLS
3
Validation
Claims, signatures, chain, validity and policy
4
Revocation & Rotation
OCSP/CRL, key rotation and expiry monitoring
5
Mediloop Trust Context
Validated identity plus separate authorization
Protocols & Standards
StandardUseKey consideration
OIDC / OAuth 2.xAuthentication and delegated authorizationValidate issuer, audience, nonce/state and scopes
SAML 2.0Enterprise federationMetadata/signature validation
X.509 / mTLSSystem and certificate trustChain, EKU, expiry and revocation
eIDAS / national eIDEU/national trustScheme-specific assurance and legal context
Certificates & PKI
Use trusted certificate authorities and validated trust stores
Validate certificate chain, hostname/use and validity
Check revocation with OCSP/CRL when required
Monitor expiration well before production outage
Support overlapping rotation of keys/certificates
Protect private keys in secure secret/key management
Trust Frameworks
National Trust

Country-specific identity providers, healthcare PKI and registries.

European Trust

eIDAS and cross-border trust arrangements as applicable.

Healthcare Trust

Professional/organization verification and care-context requirements.

Mediloop Policy

Tenant, membership, scope, consent and purpose checks remain authoritative.

Implementation Guide
1
Discover
Provider metadata / certificate requirements
2
Configure
Client, redirect, cert and trust store
3
Validate
Tokens/assertions/certificates
4
Authorize
Map only trusted claims; apply Mediloop permissions
5
Operate
Monitor expiry, revocation and provider changes
APIs & Examples
typescriptCopy
// Conceptual verifier — provider-specific adapters stay behind this boundary
const trust = await identity.verifyExternalAssertion({
  provider: 'national-idp',
  assertion,
  expectedTenantId,
});

if (!trust.verified) throw new Error('Untrusted identity');
Illustrative SDK surface; public SDK names are not commitments until published.
Security & Compliance
Reject weak/invalid signature algorithms
Pin expected issuer/audience and provider metadata
Prevent replay and token substitution
Use short-lived credentials where possible
Log security-relevant trust decisions
Regularly test rotation/revocation paths
Developer Integration Surface
SurfaceOperation / resourceUseStatus
OIDC/SAMLauthorize / callback / assertion validationUser federationStandard
mTLS / X.509TLS client auth / certificate validationSystem trustStandard
OCSP / CRLrevocation statusCertificate lifecyclePKI
Trust APIverify provider assertion / certificateMediloop connector abstractionPlanned/versioned
Next Steps
Choose federation/trust mechanism
Register provider/client and trust anchors
Implement strict validation
Separate identity claims from authorization
Test expiry/revocation/rotation
Enable ongoing monitoring