I am studying around Authentication/Authorization architecture for web services for a project.
I found SAML as a standard but it looks complex and I couldn't find good implementation and documents, in addition we may not need a standard solution.
I appreciate if you can help me on this. I am more concerned about the architecture and interfaces that would be exposed to the clients. The internal server components are less important.