SAML Token Analyzer
Decode and inflate SAML tokens, review the assertion, attributes, conditions, signature and certificate, and flag suspicious configuration — all in your browser.
SAML input
Base64, deflated redirect URL or raw XML — everything is decoded in your browser, nothing is uploaded.
What is a SAML token?
A SAML message is an XML document an identity provider hands to a service provider through the browser. On the HTTP-POST binding it is base64-encoded; on the HTTP-Redirect binding it is raw-DEFLATE compressed and then base64 + URL encoded. The assertion inside carries the subject, the validity window, the audience and the attributes your application turns into a session.
Assertion
Who the user is, when it was issued, and how long it stays valid.
Conditions
Audience restriction and time window that stop replay elsewhere.
Signature
XML signature over the assertion, with the identity provider certificate.
Encode XML back to a binding value
Paste SAML XML to produce the value you would place in a POST form field, or the deflated value for a redirect URL — handy when replaying a request during testing.