An overview of attributes available in eduGAIN can be found here, together with the eduGAIN Policy Framework Attribute Profile. The recommended attributes in eduGAIN Participant Federations ensure that Identity Providers supply a basis set of attributes, that are available in SURFconext. These recommended attributes are available, in general, for most end users across federations.

As with with services published in SURFconext, think carefully about which attributes you require or request from Identity Providers. Generally speaking, the more you need the more hesitant Identity Providers are when it comes to connecting to your service. For example, to uniquely identify users you can opt to use eduPersonPrincipalName. However, this attribute contains a lot of personally identifiable information. Instead, it would be better (from a privacy point of view) to use the SAML NameID (urn:oasis:names:tc:SAML:2.0:nameid-format:persistent). Check the 'User Identifiers' paragraph on the Attributes in SURFconext page for more info. And when you need more attributes, the likelihood of certain attributes missing for users, increases.