SAML Decoder
Decode SAML assertions from Base64-encoded XML. All processing is done in your browser for maximum security and privacy.
Decoded XML
Parsed SAML Data
Issuer
—
NameID
—
IssueInstant
—
Audience
—
NotBefore
—
NotOnOrAfter
—
AuthnContextClassRef
—
Attributes
No attributes found
| Attribute Name | Values |
|---|
How to Use SAML Decoder
Paste SAML Data
Copy the Base64-encoded SAML Response or Assertion from your SAML trace or network request
Auto Decode
The tool automatically decodes Base64 and detects deflate compression to reveal the XML
Inspect Details
View the decoded XML and extracted fields including Issuer, NameID, and attributes
What is SAML?
Security Assertion Markup Language (SAML) is an XML-based open standard for exchanging authentication and authorization data between parties, particularly between an identity provider (IdP) and a service provider (SP). SAML assertions are typically Base64-encoded and may be deflate-compressed when transmitted via HTTP redirect bindings.
SSO Authentication
SAML enables Single Sign-On, allowing users to authenticate once and access multiple services
XML-Based Assertions
SAML uses XML assertions to carry authentication and authorization statements between parties
Secure Binding
SAML supports HTTP Redirect, POST, and Artifact bindings for secure token exchange
Frequently Asked Questions
The tool supports Base64-encoded SAML Response and Assertion XML, commonly found in SAML redirects and POST bindings. It also auto-detects and inflates deflate-compressed SAML requests.
Yes. All processing happens entirely in your browser. Your SAML tokens are never sent to any server. No data leaves your device.
SAML requests sent via HTTP redirect are often deflate-compressed before Base64 encoding to reduce URL length. This tool automatically detects and decompresses such data.
A request is a samlp:AuthnRequest that the service provider sends to ask the identity provider to authenticate a user; a response is the samlp:Response coming back, carrying the saml:Assertion with the authentication statement and attributes. Both travel URL-encoded (Redirect binding) or inside an HTML form POST (POST binding). This tool decodes either direction.
An opaque string the SP attaches to the request that the IdP must return unchanged with the response - typically the URL to redirect to after login. The SAML bindings spec recommends keeping it under 80 bytes, and it carries no meaning to the IdP. When SSO lands on the wrong page, a dropped or corrupted RelayState is a prime suspect.
In the HTTP-Redirect binding the XML is raw-Deflate compressed, then Base64, then URL-encoded - the three steps the spec mandates. Give this tool the URL-encoded value: if it expands into markup starting with <, it was compressed; if it already starts with <?xml or <saml, it wasn't. POST-binding messages are Base64 without Deflate.
Clock skew - signature validation fails when SP and IdP clocks differ by more than the allowed drift; audience mismatch - the audienceRestriction in the assertion doesn't contain the SP's entity ID; and expired responses (NotOnOrAfter). Also common: a missing RelayState and unsigned assertions where the SP requires them. The decoded fields this tool shows let you check each of these directly.
Yes - decoding is not verification. The assertion's XML is readable by anyone; the signature inside covers integrity, not confidentiality. What you cannot do without the IdP's public certificate is prove the assertion is authentic and unmodified. Treat any decoded content carefully: assertions often carry email addresses, groups, and entitlements.
Related Tools
JWT Parser
Decode and verify JSON Web Tokens (JWT) on the spot. View header, payload, and signature details with easy-to-read timestamps
Certificate Decoder
Decode X.509 SSL/TLS certificates in PEM format
Base64 URL Decoder Parser
Decode and encode Base64, parse URL-encoded strings, preview Base64 images, and decode JWT header or payload segments
Authoritative References
Primary sources behind this tool - official standards and specifications, not secondhand summaries.