SAML Decoder

Decode SAML assertions from Base64-encoded XML. All processing is done in your browser for maximum security and privacy.

Auto-Detect Compression Full XML Parsing 100% Client-Side

How to Use SAML Decoder

1

Paste SAML Data

Copy the Base64-encoded SAML Response or Assertion from your SAML trace or network request

2

Auto Decode

The tool automatically decodes Base64 and detects deflate compression to reveal the XML

3

Inspect Details

View the decoded XML and extracted fields including Issuer, NameID, and attributes

What is SAML?

Security Assertion Markup Language (SAML) is an XML-based open standard for exchanging authentication and authorization data between parties, particularly between an identity provider (IdP) and a service provider (SP). SAML assertions are typically Base64-encoded and may be deflate-compressed when transmitted via HTTP redirect bindings.

SSO Authentication

SAML enables Single Sign-On, allowing users to authenticate once and access multiple services

XML-Based Assertions

SAML uses XML assertions to carry authentication and authorization statements between parties

Secure Binding

SAML supports HTTP Redirect, POST, and Artifact bindings for secure token exchange

Frequently Asked Questions

What SAML formats are supported?

The tool supports Base64-encoded SAML Response and Assertion XML, commonly found in SAML redirects and POST bindings. It also auto-detects and inflates deflate-compressed SAML requests.

Is my SAML data secure?

Yes. All processing happens entirely in your browser. Your SAML tokens are never sent to any server. No data leaves your device.

What does deflate compression mean?

SAML requests sent via HTTP redirect are often deflate-compressed before Base64 encoding to reduce URL length. This tool automatically detects and decompresses such data.

What is the difference between a SAML request and a SAML response?

A request is a samlp:AuthnRequest that the service provider sends to ask the identity provider to authenticate a user; a response is the samlp:Response coming back, carrying the saml:Assertion with the authentication statement and attributes. Both travel URL-encoded (Redirect binding) or inside an HTML form POST (POST binding). This tool decodes either direction.

What is RelayState in a SAML message?

An opaque string the SP attaches to the request that the IdP must return unchanged with the response - typically the URL to redirect to after login. The SAML bindings spec recommends keeping it under 80 bytes, and it carries no meaning to the IdP. When SSO lands on the wrong page, a dropped or corrupted RelayState is a prime suspect.

How can I tell whether SAML data is Deflate-compressed?

In the HTTP-Redirect binding the XML is raw-Deflate compressed, then Base64, then URL-encoded - the three steps the spec mandates. Give this tool the URL-encoded value: if it expands into markup starting with <, it was compressed; if it already starts with <?xml or <saml, it wasn't. POST-binding messages are Base64 without Deflate.

What causes the most common SAML errors?

Clock skew - signature validation fails when SP and IdP clocks differ by more than the allowed drift; audience mismatch - the audienceRestriction in the assertion doesn't contain the SP's entity ID; and expired responses (NotOnOrAfter). Also common: a missing RelayState and unsigned assertions where the SP requires them. The decoded fields this tool shows let you check each of these directly.

Can I decode a signed SAML assertion without the private key?

Yes - decoding is not verification. The assertion's XML is readable by anyone; the signature inside covers integrity, not confidentiality. What you cannot do without the IdP's public certificate is prove the assertion is authentic and unmodified. Treat any decoded content carefully: assertions often carry email addresses, groups, and entitlements.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}