The first two steps of the above algorithm explains explain the authorization code flow using of OIDC, applied to {{UBIK}}. For SAML, the only real difference is the reception of the IdP's response at the app, which happens via a mediator server in that case, necessarily (the SAML protocol does not support redirecting the result to a mobile app).
[[Category:SSO|Single Sign-On]]