SAML
Security Assertion Markup Language
- Pronunciation
- SAM-ul
In short
SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
What is SAML?
SAML 2.0, published by OASIS in 2005, is the long-standing standard for enterprise single sign-on. Employees log in once with the company's identity provider (IdP), such as Microsoft Entra ID, Okta or Google Workspace, and are then signed into tools such as Salesforce, Slack or AWS, the service providers (SPs), without separate passwords.
In a typical service-provider-initiated login, the app redirects the browser to the IdP with a SAML request. The user authenticates there, often with multi-factor authentication, and the IdP posts back a SAML response containing an assertion: an XML document saying who the user is, when they signed in and which attributes or groups they have, digitally signed with the IdP's key. The app verifies the signature and creates a session.
Setting up SAML means exchanging metadata between the two sides: entity IDs, URLs and the IdP's signing certificate. Because one IdP controls access to everything, companies can enforce password and MFA policies centrally and remove a departing employee's access to every app at once.
A common misconception is that SAML is outdated and can simply be replaced. Most new applications prefer OpenID Connect, but SAML remains a requirement for selling software to large organizations. Its XML signatures are also notoriously tricky: libraries that validate them incorrectly have allowed attackers to forge logins, so well-maintained libraries and careful configuration are essential.
Key takeaways
- SAML is an XML-based standard for single sign-on.
- SAML 2.0 dates from 2005 and is widespread in enterprises.
- The identity provider sends a signed assertion to the service provider.
- Central login lets companies enforce MFA and remove access everywhere.
- XML signature checks are error-prone; use mature libraries.
Readers ask
What is the difference between SAML and OAuth?
SAML is for authentication and single sign-on, passing signed XML assertions through the browser. OAuth is for authorization, giving applications access tokens for APIs. OpenID Connect adds SSO-style login on top of OAuth.
What are an identity provider and a service provider?
The identity provider (IdP) authenticates users and issues assertions, such as Okta or Entra ID. The service provider (SP) is the application the user wants to use, which trusts the IdP's assertions.
Why do enterprise customers ask for SAML?
Because it connects your app to their existing identity system, so employees use company accounts, security policies apply automatically, and access can be granted or removed centrally.
See also
- SSOSecurity, p. 41SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- OpenID ConnectSecurity, p. 23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- XMLBackend & APIs, p. 48XML (Extensible Markup Language) is a text format for structured data that uses nested tags you define yourself, readable by both people and machines.
- Digital SignatureSecurity, p. 11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
Spotted a mistake or something missing on this page?Suggest an edit