I think their reasoning on not being an identify provider but acting solely downstream is very clever.
Y? What's wrong with providing username/password authentication
Y? What's wrong with providing username/password authentication