Tools › Encoding
SAML Decoder
Decode a SAML message, the sign-on data passed between an identity provider and a service, and see what matters when single sign-on fails: issuer, audience, NameID, attributes, validity times against your clock, status and signature algorithms.
About this tool What it's for, how to use it and an example
What it's for
Read a SAML message: the XML that an identity provider (IdP, such as Entra ID, Okta or AD FS) and a service provider (SP, the application) pass through the browser during single sign-on. It shows who sent it, who it’s for, who signed in, the attributes sent, and the times it’s valid between, compared with this device’s clock.
For example, when sign-on to an application fails with a vague error, copy the SAMLResponse from the browser’s developer tools (or a captured network log) and paste it here to see whether it has expired, is for the wrong audience, carries a failure status, or is signed with SHA-1.
How to use it
Paste any of these, and it’s decoded as you type:
- The Base64 value of a
SAMLResponseorSAMLRequestform field (the HTTP-POST binding). - A whole link with
SAMLRequest=orSAMLResponse=in it, or a form body; the value is taken from it. In a link (the HTTP-Redirect binding) the XML is also compressed with deflate, which is undone. - The XML itself.
The message line says how it was read. Below it are anything worth looking at (errors first), a summary with a Copy button on each value, the attributes, and the XML laid out with indents.
Example
Paste this (a made-up request, Base64 of its XML):
PHNhbWxwOkF1dGhuUmVxdWVzdCB4bWxuczpzYW1scD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnByb3RvY29sIiBJRD0iX3ExIiBBc3NlcnRpb25Db25zdW1lclNlcnZpY2VVUkw9Imh0dHBzOi8vc3AuZXhhbXBsZS5jb20vYWNzIj48c2FtbDpJc3N1ZXIgeG1sbnM6c2FtbD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFzc2VydGlvbiI+aHR0cHM6Ly9zcC5leGFtcGxlLmNvbTwvc2FtbDpJc3N1ZXI+PC9zYW1scDpBdXRoblJlcXVlc3Q+
The message says it was read from Base64 and nothing looks wrong. The summary shows the type AuthnRequest, the
issuer https://sp.example.com, the ID _q1 and the assertion consumer service https://sp.example.com/acs.
Good to know
It doesn’t check signatures: that needs the IdP’s certificate and the exact signed bytes, and is the service provider’s job. It only names the algorithms. An encrypted assertion can’t be read without the SP’s private key. Times are compared with this device’s clock, so a wrong clock here gives wrong warnings.
A SAMLResponse is a sign-on pass: until it expires, someone could use it to sign in as that person. It isn’t saved or put in a link, and there’s no “Open in…” for it, but treat it like a password: don’t paste it into chats or tickets until it has expired.
Attributes
Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.
Saved you a few minutes? Say thanks with a coffee.
Something wrong with this tool, or missing from it? Report a bug or suggest a feature.