Neatbo.

Inspect SAML assertions locally: issuer, audience and dates

Inspect SAML XML or Base64 without uploading assertions. Compare issuer, audience and time fields, and understand why parsing is not signature verification.

Prepare an assertion

The inspector accepts XML or standard Base64-encoded XML. Start with the fictional example on the tool page to see the output shape.

The root must be Assertion or Response. The tool does not start a login flow, inspect cookies or contact your identity provider.

Compare the important fields

Issuer identifies the claimed issuer, Audience the claimed recipient and NameID the subject identifier. Compare exact values against your service configuration.

Conditions preserves attributes such as NotBefore and NotOnOrAfter. Compare their original values with UTC timestamps from your identity system logs.

A signature element is not a verified signature

signaturePresent only indicates that a Signature element exists. signatureVerified remains false: this tool does not verify XML signatures, certificate chains or recipient trust.

Do not use parsed output as authentication evidence. Your service provider must perform protocol validation, trusted-key checks, time checks and replay protection.

Clear sensitive input after inspection

Parsing runs in this browser without sending input to Neatbo servers. External entities and DTDs are rejected.

Assertions can contain identity information and live login material. Remove real identifiers before sharing a debugging sample; this tool does not automatically redact them.

Separate a readable message from a trusted login

Start with a fictional Assertion rather than a live login response. Check the raw XML alongside the extracted fields so you can see whether a value belongs to the expected element. A convenience summary is not a complete protocol validator.

For an actual authentication failure, compare the service-provider error with its configured issuer, recipient, audience and time policy. The service provider, using trusted configuration, remains responsible for signature checks and replay protection. This tool does not validate those policies for you.

Separate a readable message from a trusted login
FieldWhat to compareWhat it does not prove
IssuerExact configured identifierThe issuer signed this message
AudienceExpected service identifierThe recipient is authorized
NotBefore / NotOnOrAfterUTC values and service policyThe assertion is currently accepted
signaturePresentWhether a Signature element existsSignature or certificate validity
A fictional example to try
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion">
  <Issuer>https://idp.example.test</Issuer>
  <Subject><NameID>demo-user</NameID></Subject>
</Assertion>

Before you finish

  • This sample is fictional and unsigned.
  • Check original UTC values rather than relying on a local-time display.
  • Remove identifiers and login material before sharing a sample.
  • Never treat signatureVerified: false as a successful trust check.

References

  • OASIS: SAML 2.0 Core

    Protocol reference for assertion elements and conditions. This inspector does not implement complete SAML trust validation.

Tools used in this article

SAML response inspector →Decode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.Unicode escape →Convert Unicode escapes into readable text and back.