SAML response inspector
Decode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.
- 1Add input
- 2Review and run
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Paste a SAMLResponse field, Base64 payload or SAML 2.0 XML to inspect the fields used when troubleshooting SSO. Compare the response and assertion values with your IdP and service provider configuration. Everything stays in this browser.
How to use this tool
- In your browser network panel, copy the SAMLResponse value from the SSO POST, or use a SAML 2.0 XML file.
- Paste the Base64 value, SAMLResponse= field or XML; alternatively choose a UTF-8 .xml or .txt file. The input check identifies the document before you run.
- Select “Inspect response” and compare Status, Issuer, Destination, InResponseTo, audience, recipient, NameID and attributes. Save the JSON only if needed.
Supported inputs and limits
This is a structural inspector. It does not verify XML signatures, certificates, issuer trust, identity claims or assertion validity.
Encrypted assertions cannot be read without a decryption key; the tool only reports their count.
The browser processes your input locally. The source and JSON result may contain sensitive identities and attributes. Clear or close the tab when finished.
Worked example
Example input
<p:Response xmlns:p="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:a="urn:oasis:names:tc:SAML:2.0:assertion" ID="_r1" Version="2.0"><a:Issuer>https://idp.example.test</a:Issuer><p:Status><p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></p:Status><a:Assertion ID="_a1" Version="2.0"><a:Issuer>https://idp.example.test</a:Issuer><a:Subject><a:NameID>[email protected]</a:NameID></a:Subject></a:Assertion></p:Response>
Example options
{}Example output
{
"kind": "Response",
"inputEncoding": "XML",
"response": {
"id": "_r1",
"version": "2.0",
"issueInstant": null,
"issuer": "https://idp.example.test",
"destination": null,
"inResponseTo": null,
"statusCode": "urn:oasis:names:tc:SAML:2.0:status:Success",
"statusSubcodes": [],
"statusMessage": null,
"signaturePresent": false
},
"assertions": [
{
"id": "_a1",
"version": "2.0",
"issueInstant": null,
"issuer": "https://idp.example.test",
"signaturePresent": false,
"subject": {
"nameId": "[email protected]",
"nameIdFormat": null,
"confirmations": []
},
"conditions": null,
"authnStatements": [],
"attributes": []
}
],
"encryptedAssertions": 0,
"signatureVerified": false
}When something does not work
If the check fails, copy the complete Base64 SAMLResponse value or the XML root document. Only SAML 2.0 Response and Assertion namespaces are accepted.
Frequently asked questions
What can I paste?
A SAML 2.0 Response or Assertion XML document, its Base64 encoding, or a SAMLResponse= form field from a POST payload. Other XML and encrypted assertion contents are not decoded.
Does a present signature or Success status mean the login is trusted?
No. Presence and declared status are displayed as fields only. This tool does not perform cryptographic verification, trust checks, replay checks or SAML profile validation.
Is my SAML response uploaded?
No. The tool executes in your browser. Input and results can remain in this tab’s temporary workspace until you clear it, refresh or close the tab.
Documentation & further reading
Related tools
Base64 encode / decode
Encode or decode a snippet in a click.
URL encode / decode
Make those encoded characters readable again.
HTML entities
Convert between HTML entities and readable characters.
Unicode escape
Convert Unicode escapes into readable text and back.