Inspect SAML assertions locally: issuer, audience and dates
Inspect SAML XML or Base64 without uploading assertions. Compare issuer, audience and time fields, and understand why parsing is not signature verification.
Prepare an assertion
The inspector accepts XML or standard Base64-encoded XML. Start with the fictional example on the tool page to see the output shape.
The root must be Assertion or Response. The tool does not start a login flow, inspect cookies or contact your identity provider.
Compare the important fields
Issuer identifies the claimed issuer, Audience the claimed recipient and NameID the subject identifier. Compare exact values against your service configuration.
Conditions preserves attributes such as NotBefore and NotOnOrAfter. Compare their original values with UTC timestamps from your identity system logs.
A signature element is not a verified signature
signaturePresent only indicates that a Signature element exists. signatureVerified remains false: this tool does not verify XML signatures, certificate chains or recipient trust.
Do not use parsed output as authentication evidence. Your service provider must perform protocol validation, trusted-key checks, time checks and replay protection.
Clear sensitive input after inspection
Parsing runs in this browser without sending input to Neatbo servers. External entities and DTDs are rejected.
Assertions can contain identity information and live login material. Remove real identifiers before sharing a debugging sample; this tool does not automatically redact them.
Separate a readable message from a trusted login
Start with a fictional Assertion rather than a live login response. Check the raw XML alongside the extracted fields so you can see whether a value belongs to the expected element. A convenience summary is not a complete protocol validator.
For an actual authentication failure, compare the service-provider error with its configured issuer, recipient, audience and time policy. The service provider, using trusted configuration, remains responsible for signature checks and replay protection. This tool does not validate those policies for you.
| Field | What to compare | What it does not prove |
|---|---|---|
| Issuer | Exact configured identifier | The issuer signed this message |
| Audience | Expected service identifier | The recipient is authorized |
| NotBefore / NotOnOrAfter | UTC values and service policy | The assertion is currently accepted |
| signaturePresent | Whether a Signature element exists | Signature or certificate validity |
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion">
<Issuer>https://idp.example.test</Issuer>
<Subject><NameID>demo-user</NameID></Subject>
</Assertion>Before you finish
- This sample is fictional and unsigned.
- Check original UTC values rather than relying on a local-time display.
- Remove identifiers and login material before sharing a sample.
- Never treat signatureVerified: false as a successful trust check.
References
- OASIS: SAML 2.0 Core
Protocol reference for assertion elements and conditions. This inspector does not implement complete SAML trust validation.