Shibboleth IdP is a self-hosted SAML identity provider for federated SSO and institutional identity workflows. The current stable version is Shibboleth IDP v5.x, with v4 reaching end-of-life on September 1, 2024.
- SAML 2.0-based SSO with support for advanced profile implementations
- Federation support with eduGAIN and other identity federations
- Enhanced attribute resolution and release policies
- Modern architecture built on Spring Framework with improved modularity
- Integration with external MFA systems (including privacyIDEA)
- Enhanced monitoring and diagnostic capabilities
- Plugin architecture for custom functionality
- Current Stable Version: Shibboleth IDP v5.2.1 (as of February 2026)
- Previous Stable Version: Shibboleth IDP v5.1.x
- Legacy Version: Shibboleth IDP v4.3.3 (end-of-life: September 1, 2024)
- Requirements: Java 17 (required for v5 - Java 8/11 no longer supported)
- Compatible Servlet Containers: Jetty 11 or Tomcat 10.1
Note: Upgrading to v5 is critical for continued security patches and support. Version 4 no longer receives security updates.