Neatbo.

SAML response inspector

Decode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.

Browser-local processingInputSAMLResponse / SAML XMLOutputStructured view / JSONUp to 1 MiB per file · File limit: 1
  1. 1Add input
  2. 2Review and run
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

Input check

Paste the SAMLResponse value copied from your browser network panel, a SAMLResponse= form field, or complete SAML 2.0 XML.

Paste a response to begin.

Input stays in this browser. Inspection does not validate signatures or identity.

SAML input source
0 characters · 0 bytes
Preparing the tool…

Before you start

Paste a SAMLResponse field, Base64 payload or SAML 2.0 XML to inspect the fields used when troubleshooting SSO. Compare the response and assertion values with your IdP and service provider configuration. Everything stays in this browser.

How to use this tool

  1. In your browser network panel, copy the SAMLResponse value from the SSO POST, or use a SAML 2.0 XML file.
  2. Paste the Base64 value, SAMLResponse= field or XML; alternatively choose a UTF-8 .xml or .txt file. The input check identifies the document before you run.
  3. Select “Inspect response” and compare Status, Issuer, Destination, InResponseTo, audience, recipient, NameID and attributes. Save the JSON only if needed.

Supported inputs and limits

This is a structural inspector. It does not verify XML signatures, certificates, issuer trust, identity claims or assertion validity.

Encrypted assertions cannot be read without a decryption key; the tool only reports their count.

The browser processes your input locally. The source and JSON result may contain sensitive identities and attributes. Clear or close the tab when finished.

Worked example

Example input

<p:Response xmlns:p="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:a="urn:oasis:names:tc:SAML:2.0:assertion" ID="_r1" Version="2.0"><a:Issuer>https://idp.example.test</a:Issuer><p:Status><p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></p:Status><a:Assertion ID="_a1" Version="2.0"><a:Issuer>https://idp.example.test</a:Issuer><a:Subject><a:NameID>[email protected]</a:NameID></a:Subject></a:Assertion></p:Response>
Example options
{}

Example output

{
  "kind": "Response",
  "inputEncoding": "XML",
  "response": {
    "id": "_r1",
    "version": "2.0",
    "issueInstant": null,
    "issuer": "https://idp.example.test",
    "destination": null,
    "inResponseTo": null,
    "statusCode": "urn:oasis:names:tc:SAML:2.0:status:Success",
    "statusSubcodes": [],
    "statusMessage": null,
    "signaturePresent": false
  },
  "assertions": [
    {
      "id": "_a1",
      "version": "2.0",
      "issueInstant": null,
      "issuer": "https://idp.example.test",
      "signaturePresent": false,
      "subject": {
        "nameId": "[email protected]",
        "nameIdFormat": null,
        "confirmations": []
      },
      "conditions": null,
      "authnStatements": [],
      "attributes": []
    }
  ],
  "encryptedAssertions": 0,
  "signatureVerified": false
}

When something does not work

If the check fails, copy the complete Base64 SAMLResponse value or the XML root document. Only SAML 2.0 Response and Assertion namespaces are accepted.

Frequently asked questions

What can I paste?

A SAML 2.0 Response or Assertion XML document, its Base64 encoding, or a SAMLResponse= form field from a POST payload. Other XML and encrypted assertion contents are not decoded.

Does a present signature or Success status mean the login is trusted?

No. Presence and declared status are displayed as fields only. This tool does not perform cryptographic verification, trust checks, replay checks or SAML profile validation.

Is my SAML response uploaded?

No. The tool executes in your browser. Input and results can remain in this tab’s temporary workspace until you clear it, refresh or close the tab.

Documentation & further reading

Related tools