thoughtasylumTOOLBOX Preview

Tools › Encoding

SAML Decoder

Decode a SAML message, the sign-on data passed between an identity provider and a service, and see what matters when single sign-on fails: issuer, audience, NameID, attributes, validity times against your clock, status and signature algorithms.

About this tool What it's for, how to use it and an example

What it's for

Read a SAML message: the XML that an identity provider (IdP, such as Entra ID, Okta or AD FS) and a service provider (SP, the application) pass through the browser during single sign-on. It shows who sent it, who it’s for, who signed in, the attributes sent, and the times it’s valid between, compared with this device’s clock.

For example, when sign-on to an application fails with a vague error, copy the SAMLResponse from the browser’s developer tools (or a captured network log) and paste it here to see whether it has expired, is for the wrong audience, carries a failure status, or is signed with SHA-1.

How to use it

Paste any of these, and it’s decoded as you type:

  • The Base64 value of a SAMLResponse or SAMLRequest form field (the HTTP-POST binding).
  • A whole link with SAMLRequest= or SAMLResponse= in it, or a form body; the value is taken from it. In a link (the HTTP-Redirect binding) the XML is also compressed with deflate, which is undone.
  • The XML itself.

The message line says how it was read. Below it are anything worth looking at (errors first), a summary with a Copy button on each value, the attributes, and the XML laid out with indents.

Example

Paste this (a made-up request, Base64 of its XML):

PHNhbWxwOkF1dGhuUmVxdWVzdCB4bWxuczpzYW1scD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnByb3RvY29sIiBJRD0iX3ExIiBBc3NlcnRpb25Db25zdW1lclNlcnZpY2VVUkw9Imh0dHBzOi8vc3AuZXhhbXBsZS5jb20vYWNzIj48c2FtbDpJc3N1ZXIgeG1sbnM6c2FtbD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFzc2VydGlvbiI+aHR0cHM6Ly9zcC5leGFtcGxlLmNvbTwvc2FtbDpJc3N1ZXI+PC9zYW1scDpBdXRoblJlcXVlc3Q+

The message says it was read from Base64 and nothing looks wrong. The summary shows the type AuthnRequest, the issuer https://sp.example.com, the ID _q1 and the assertion consumer service https://sp.example.com/acs.

Good to know

It doesn’t check signatures: that needs the IdP’s certificate and the exact signed bytes, and is the service provider’s job. It only names the algorithms. An encrypted assertion can’t be read without the SP’s private key. Times are compared with this device’s clock, so a wrong clock here gives wrong warnings.

A SAMLResponse is a sign-on pass: until it expires, someone could use it to sign in as that person. It isn’t saved or put in a link, and there’s no “Open in…” for it, but treat it like a password: don’t paste it into chats or tickets until it has expired.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close