不喜欢广告? 无广告 今天

SAML Response Decoder

开发人员安全
广告 移除?

概括

场地 价值
结果将显示在这里

Decoded XML

广告 移除?

指导

SAML Response Decoder

SAML Response Decoder

Paste a base64-encoded SAML response or assertion and instantly see the decoded XML alongside a summary of the most important fields. Handles URL-encoded payloads and DEFLATE-compressed strings used by SAML’s HTTP-Redirect binding, all in your browser — nothing is uploaded.

如何使用

  1. Capture the SAML response from your IdP — usually a hidden form field named SAMLResponse on the ACS POST, or the SAMLRequest query parameter for HTTP-Redirect.
  2. Paste the raw value into the input box. URL-encoding, DEFLATE compression and zlib/gzip wrappers are detected automatically.
  3. Read the Summary table for at-a-glance details: Issuer, NameID, NotBefore / NotOnOrAfter, Audience, Destination, SessionIndex and attribute statements.
  4. Use the formatted XML view (with copy and download buttons) for deeper inspection or to share with a colleague.

特征

  • Auto-detect encoding – Handles base64, URL-encoded base64, and DEFLATE-compressed payloads from the HTTP-Redirect binding without extra clicks.
  • Summary highlights – Surfaces NameID, Audience, Issuer, Status, Destination, NotBefore / NotOnOrAfter and SessionIndex so you can spot integration issues at a glance.
  • Validity check – Compares the assertion’s NotOnOrAfter against the current time and flags expired tokens.
  • Pretty-printed XML – Indented, syntax-highlighted output with copy and download actions.
  • 隐私优先 – All decoding happens locally in your browser. SAML responses never touch our servers.

常问问题

  1. What is SAML and how does it work?

    SAML (Security Assertion Markup Language) is an XML-based open standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP). The IdP authenticates the user, then issues a signed XML assertion that the SP trusts to grant access — enabling Single Sign-On across independent web applications.

  2. What is the difference between a SAML Response and a SAML Assertion?

    A SAML Response is the outer envelope sent from the IdP to the SP and includes protocol-level metadata such as Status, Destination and InResponseTo. The SAML Assertion is the payload inside that response — it carries the actual identity claims: NameID, AuthnStatement, Conditions and AttributeStatement. A response can wrap one or more assertions.

  3. What do NotBefore and NotOnOrAfter mean in a SAML assertion?

    NotBefore and NotOnOrAfter are time-window attributes inside the Conditions element that define when an assertion is valid. The SP must reject any assertion presented before NotBefore or at/after NotOnOrAfter. The window is usually only a few minutes wide to limit replay attacks, which is why clock skew between IdP and SP is a common cause of SAML failures.

  4. What is the AudienceRestriction and why does it matter?

    AudienceRestriction names the intended Service Provider (the SP's entity ID) for the assertion. The SP must reject assertions whose Audience does not match its own configured entity ID. This binding prevents an assertion issued for one application from being replayed against another — even if both trust the same IdP.

  5. What is the difference between HTTP-Redirect and HTTP-POST bindings?

    HTTP-Redirect places the SAML message in a URL query string, so it must be DEFLATE-compressed and base64-encoded to fit. It is typically used for AuthnRequests sent from SP to IdP. HTTP-POST submits the message as a hidden form field, which has no size limit and does not require compression — it is the binding used for the SAML response back from IdP to SP.

想要享受无广告的体验吗? 立即无广告

安装我们的扩展

将 IO 工具添加到您最喜欢的浏览器,以便即时访问和更快地搜索

添加 Chrome 扩展程序 添加 边缘延伸 添加 Firefox 扩展 添加 Opera 扩展

记分板已到达!

记分板 是一种有趣的跟踪您游戏的方式,所有数据都存储在您的浏览器中。更多功能即将推出!

广告 移除?
广告 移除?
广告 移除?

新闻角 包含技术亮点

参与其中

帮助我们继续提供有价值的免费工具

给我买杯咖啡
广告 移除?