Skip to main content
Book 07 · SecurityPage 36 of 50

SAML

Security Assertion Markup Language

Pronunciation
SAM-ul
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/saml

In short

SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.

What is SAML?

SAML 2.0, published by OASIS in 2005, is the long-standing standard for enterprise single sign-on. Employees log in once with the company's identity provider (IdP), such as Microsoft Entra ID, Okta or Google Workspace, and are then signed into tools such as Salesforce, Slack or AWS, the service providers (SPs), without separate passwords.

In a typical service-provider-initiated login, the app redirects the browser to the IdP with a SAML request. The user authenticates there, often with multi-factor authentication, and the IdP posts back a SAML response containing an assertion: an XML document saying who the user is, when they signed in and which attributes or groups they have, digitally signed with the IdP's key. The app verifies the signature and creates a session.

Setting up SAML means exchanging metadata between the two sides: entity IDs, URLs and the IdP's signing certificate. Because one IdP controls access to everything, companies can enforce password and MFA policies centrally and remove a departing employee's access to every app at once.

A common misconception is that SAML is outdated and can simply be replaced. Most new applications prefer OpenID Connect, but SAML remains a requirement for selling software to large organizations. Its XML signatures are also notoriously tricky: libraries that validate them incorrectly have allowed attackers to forge logins, so well-maintained libraries and careful configuration are essential.

Key takeaways

  • SAML is an XML-based standard for single sign-on.
  • SAML 2.0 dates from 2005 and is widespread in enterprises.
  • The identity provider sends a signed assertion to the service provider.
  • Central login lets companies enforce MFA and remove access everywhere.
  • XML signature checks are error-prone; use mature libraries.

Readers ask

What is the difference between SAML and OAuth?

SAML is for authentication and single sign-on, passing signed XML assertions through the browser. OAuth is for authorization, giving applications access tokens for APIs. OpenID Connect adds SSO-style login on top of OAuth.

What are an identity provider and a service provider?

The identity provider (IdP) authenticates users and issues assertions, such as Okta or Entra ID. The service provider (SP) is the application the user wants to use, which trusts the IdP's assertions.

Why do enterprise customers ask for SAML?

Because it connects your app to their existing identity system, so employees use company accounts, security policies apply automatically, and access can be granted or removed centrally.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings