For WS, you can take a look at ws-security tokens (username, x509) and then utilize saml assertions. View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4186540#4186540 Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4186540