SAML Inspector
Decode a SAMLResponse or AuthnRequest and see who it logs in, for which service and until when — with checks for unsigned assertions, signature wrapping and comment tricks.
How to use
- Paste the SAMLResponse (Base64), a SAML URL, or the XML — from your browser’s network tab or a SAML tracer.
- Read the user, audience, time window and the findings.
- Enter your SP’s entity ID and ACS URL for a clear accept / reject.
Common questions
How do I get the SAMLResponse to decode?
In your browser’s developer tools, open the Network tab, sign in, and find the POST to your application’s ACS URL: the SAMLResponse form field is the value to paste. A SAML tracer extension shows it too.
Why does my SAML login fail?
The most common causes are an audience that doesn’t match the SP entity ID, a wrong ACS (Recipient) URL, clock skew between servers, and a changed IdP signing certificate. “Check it like your SP” tests each of these.
Does this verify the SAML signature?
It finds the signatures and checks them for the structural attacks behind real breaches (signature wrapping, unsigned assertions, comment truncation). Verifying the cryptography needs the IdP certificate in your SP.
Known limitations
- Signatures are located and checked for structural attacks, but not cryptographically verified (that needs XML canonicalisation and the IdP’s certificate in your SP).
- Encrypted assertions cannot be read: they need the SP’s private key, which should never be pasted into a website.
- SAML 2.0 only. Messages with a DOCTYPE are refused on purpose (XML entity attacks).
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- OASIS SAML 2.0 Core (opens in a new tab)
- OASIS SAML 2.0 Bindings (POST, Redirect) (opens in a new tab)
- OASIS SAML 2.0 Profiles (Web SSO) (opens in a new tab)
- OWASP SAML Security Cheat Sheet (opens in a new tab)
- W3C XML Signature (opens in a new tab)
- CVE-2017-11427 — comment truncation (opens in a new tab)