Skip to content Skip to site navigation Skip to service navigation

SAML Attribute Release Policy

For many SAML-enabled sites to allow a user to access protected materials, certain information about the user must be provided. Some sites need to know name, e-mail address, or a specific entitlement (Stanford handles entitlement through workgroup memberships). Some others merely want to know whether the user is Stanford faculty, staff, or student, and don’t depend upon the particular identity of the user in question — only that Stanford is willing to vouch for them. For sites using SAML on campus, attribute release policies are commensurate with the policies for sites using Stanford Authentication and Authorization (SAML or WebAuth).

Default Attribute Release

To simplify the attribute release, we have implemented the default attribute release for qualified Service Providers (SPs). The blanket attribute release includes the following attributes:

Attribute SAML Name Description and Example
uid  urn:oid:0.9.2342.19200300.100.1.1 SUNet ID,  jdoe 
eduPersonPrincipalName urn:oid: SUNet ID + , 
mail* urn:oid:0.9.2342.19200300.100.1.3
givenName urn:oid: first name, ex: john 
sn urn:oid: surname/last name , ex: doe 
displayName urn:oid:2.16.840.1.113730.3.1.241 Prof. John Doe
eduPersonAffiliation urn:oid: faculty
eduPersonScopedAffiliation urn:oid:
suAffilliation suAffiliation stanford:faculty (but see also the note below)
eduPersonEntitlement** urn:oid: stem_x:workgroup_y (see note #6)
*WARNING! The mail attribute is not a mandatory attribute at Stanford and might have no value for some users. In particular, if your SP creates an account using one of the attributes as the identifier for that account, do NOT use the mail attribute for that identifier!


  1. InCommon Research and Scholarship SPs are included in the above default attribute release.
  2. Stanford faculty and staff member can request to release the above attributes to InCommon SPs via Help ticket.
  3. Other attributes that a person has set to "world" visible in StanfordYou may also be released.
  4. If you need any other attributes, please file a data owner approval request clearly stating your entityID and the desired attributes.
  5. For SPs that are unable to consume the default attribute release and need the IdP to perform additional transformation for attribute names or format; additional charges may apply.
  6. To release workgroup information (as eduPersonEntitlement) to specific SPs, please include exact stem/workgroup and submit a Help ticket. No special approval needed for public workgroups.
  7. The suAffilliation attribute is specific to Stanford and will not be recognized by most Service Providers; use eduPersonAffiliation or eduPersonScopedAffiliation instead. See the Directory Service: People Tree page for more detail on the suAffilliation attribute.
  8. Sample attribute-map.xml .
  9. The new default attribute release policy automatically applies to “new” SPs that joined the FarmFed Federation on or after Feb. 10, 2017.
Last modified October 29, 2020