What Is SAML Authentication?

SAML (Security Assertion Markup Language) is a protocol that allows authentication information to be securely exchanged between systems.

The SAML protocol is used in many systems during the authentication process. You can think of authentication simply as the user signing in and having their identity verified.

SAML stands for Security Assertion Markup Language.

Thanks to this protocol, a user’s identity information can be securely passed from one system to another.


How Does SAML Work?

With SAML, a user:

  1. Signs in to System A
  2. Gets authenticated
  3. Doesn’t need to sign in again when moving to System B

This mechanism is generally known as Single Sign-On (SSO).

As a result:

SAML typically carries the following information between systems:


The Technical Structure of SAML

SAML is an XML-based protocol.

Authentication information is transmitted between systems as a SAML Assertion, an XML-formatted structure.

The SAML standard was developed and published by OASIS (Organization for the Advancement of Structured Information Standards).


SAML Components

SAML’s architecture has two core components.

Service Provider (SP)

The Service Provider is the application the user wants to access.

For example:

The user ultimately wants to sign in to this system.


Identity Provider (IdP)

The Identity Provider is the system that authenticates users.

This service:

Examples of Identity Providers:


My Sample SAML Service Provider (SP) Repo

Below I’m sharing a screenshot and GitHub repo link for a simple Service Provider (SP) I built using SAML.

This app lets you quickly test SAML integration against various Identity Provider (IdP) services.

I built it with Node.js. To make setup easier, I moved it to a Docker container architecture and published it on GitHub.

You can clone the project and have it running in just a few minutes to run your own SAML integration tests.

GitHub Repo

Live Demo

SAML authentication screenshot

Features