Examples
Worked examples
- Is an instance
A researcher at a US university that participates in InCommon can log into a European-hosted research repository or data service using her home institution's credentials, provided that repository's identity provider is connected to a federation that participates in eduGAIN -- the login works because eduGAIN links InCommon and the European federation together, not because the repository built a direct integration with the researcher's specific university.
- Is an instance
A publisher offering federated single sign-on to licensed content joins eduGAIN once, publishing SAML metadata under the eduGAIN Metadata Profile, rather than separately joining every national federation whose member institutions it wants to authenticate.
Counter-examples
Looks similar, but isn't
- Not an instance
A resource that only supports direct username/password login, with no SAML identity-provider integration at all, is not reachable through eduGAIN -- interfederation only helps when both sides (the user's home federation and the service) participate in the SAML-based federated-access ecosystem in the first place.
- Not an instance
A service that has joined only a single national federation (for example, only the UK federation, with no eduGAIN participation) will not be discoverable to users from federations outside that one country, even though the underlying protocol (SAML) is the same one eduGAIN uses.
Editorial commentary
What eduGAIN is
eduGAIN is an interfederation service operated by GÉANT, the pan-European research-and-education networking organization, that connects independently operated national and regional identity federations — such as InCommon in the United States, the UK federation, Germany’s DFN-AAI, and dozens of others worldwide — into a single interoperable trust framework. Its purpose is to enable federated single sign-on across federation and country boundaries: a user authenticates once with their home institution, and that authentication can be trusted by a service provider belonging to a different, eduGAIN-connected federation, without the service provider having to establish a separate direct relationship with the user’s home federation.
Relationship to SAML and Shibboleth
eduGAIN operates at the protocol and policy layer above individual federations. Participating identity providers and service providers exchange SAML 2.0 assertions, following the SAML2int interoperability profile, and publish their metadata according to the eduGAIN Metadata Profile so that entities across different federations can discover and trust one another automatically. Shibboleth is the most widely deployed software implementation of a SAML identity provider and service provider within this ecosystem — it was designed with exactly this kind of large, multi-federation deployment in mind — but eduGAIN itself is not tied to any single software stack; any SAML-compliant identity or service provider that meets the metadata and policy requirements can participate. For a related layer built on top of federated access rather than beneath it, see SeamlessAccess, which helps users discover and select their correct identity provider at a resource’s login screen.
Why it matters for institutional access to research infrastructure
Without an interfederation service, a publisher, data repository, or research-infrastructure provider offering federated login would need to separately negotiate and maintain trust with every national federation whose users it wants to authenticate — an arrangement that does not scale globally. By joining eduGAIN once, a service becomes reachable to users from any connected federation. This underpins federated access to licensed publisher content, cross-border research data infrastructure, and multi-country collaboration platforms that need to authenticate visiting researchers against their own home institution’s credentials rather than issuing a separate account. It plays the same enabling role for identity that the Globus ecosystem plays for large-scale research data transfer — infrastructure that only works at scale because it is federated rather than bilateral.
Governance and scope
eduGAIN is a GÉANT service, but participation is not limited to Europe — national federations from the Americas, Asia-Pacific, and elsewhere participate under eduGAIN’s common policy framework, alongside European federations. Each national federation independently vets and manages its own member institutions and services; eduGAIN’s role is to interconnect those already-vetted federations rather than to vet individual institutions itself.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="eduGAIN"
vocab-term-identifier="https://casrai.org/dictionary/term/edugain" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/edugain",
"name": "eduGAIN",
"identifier": "https://casrai.org/dictionary/term/edugain",
"description": "eduGAIN is an interfederation service, operated by GÉANT, that interconnects independently operated national and regional research-and-education identity federations (such as InCommon in the United States, the UK federation, and their counterparts in dozens of other countries) under a common technical and policy framework. It does not issue identities or authenticate users directly -- it lets a service provider that trusts its own national federation extend that trust to users from any other eduGAIN-connected federation, and vice versa, without negotiating bilateral trust agreements one federation at a time.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/data-infrastructure#set",
"url": "https://casrai.org/dictionary/term/edugain",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-08-22T09:26:04",
"dateModified": "2026-09-04T07:25:32",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







