# Attributes in the Service Provider Federation

**URL:** <https://forum.clarin.eu/t/attributes-in-the-service-provider-federation/407>\
**Category:** Service Provider Federation\
**Created:** [15 August 2024 13:10 UTC](https://forum.clarin.eu/t/attributes-in-the-service-provider-federation/407 "2024-08-15T13:10:08Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![alekoe](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.clarin.eu/alekoe/32/4_2.png) [@alekoe](https://forum.clarin.eu/u/alekoe)\
**Post date:** [15 August 2024 13:10 UTC](https://forum.clarin.eu/t/attributes-in-the-service-provider-federation/407/1 "2024-08-15T13:10:08Z")

</div>

What kind of attributes are needed to connect to a CLARIN Service Provider?

The **minimal** set of required attributes:

- [eduPersonPrincipalName](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonPrincipalName) (preferred) _or_ [eduPersonTargetedID](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonTargetedID) (fall back)

Note: Some CLARIN services are not able to work properly with [eduPersonTargetedID](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonTargetedID), thus for all cases [eduPersonPrincipalName](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonPrincipalName) is preferred over [eduPersonTargetedID](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonTargetedID).

If none of the attributes above are released by the user’s Identity Provider, the user will not be able to use most CLARIN services.

The **ideal** set of attributes:

- [eduPersonPrincipalName](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonPrincipalName) (preferred) _or_ [eduPersonTargetedID](https://www.internet2.edu/media/medialibrary/2013/09/04/internet2-mace-dir-eduperson-201203.html#eduPersonTargetedID) (fall back)
- [mail](https://rnd.feide.no/attribute/mail/)
- [cn](https://rnd.feide.no/attribute/cn/) (common name)
- [o](https://rnd.feide.no/attribute/o/) (organizationName) _or_ [schacHomeOrganization](http://wiki.rediris.es/gtschema/Iriseduperson#schacHomeOrganization)

If not all of the attributes above are released by the user’s Identity Provider, the user might be asked to provide these fields upon first login. This lessens the privacy and usability of the application, since user data needs to be stored (persistently) outside the user’s home IdP. It is also a burden to application developers, who then have to design their application to comprehensively deal with missing attributes.
