Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
OASIS SAML 2.0 & XML-DSig OpenID Connect Core 1.0 XSW Vulnerability Scanner RFC 7636 PKCE S256

SAML 2.0 & OpenID Connect (OIDC) Enterprise Identity Federation Studio

An engineering workbench for enterprise Single Sign-On (SSO): decode Base64 SAML responses, inspect XML-DSig signatures and canonicalization nodes, simulate XML Signature Wrapping (XSW 1–8) exploits, compare SAML vs OIDC protocols, generate cryptographic PKCE challenges, and synthesize production Service Provider integrations.

user@enterprise.com
Authenticated Subject (NameID)
Valid XML-DSig
Cryptographic Signature
Protected
XSW Attack Exposure
S256 (SHA-256)
OIDC PKCE Binding

Interactive SAML 2.0 Assertion & XML-DSig Signature Inspector

Paste a Base64-encoded SAMLResponse or raw XML assertion to decode attributes, verify conditions (NotBefore / NotOnOrAfter), and inspect XML-DSig cryptographic signing references.

http://www.okta.com/exk123
IdP EntityID (Issuer)
https://app.example.com/saml
Audience Restriction
Valid Window
NotBefore / NotOnOrAfter
RSA-SHA256
Signature Algorithm
EXTRACTED SAML USER ATTRIBUTES & CLAIMS
SAML Attribute Name (Friendly / URI) Claim Value Enterprise Mapping
DECODED FORMATTED XML STRUCTURE

XML Signature Wrapping (XSW 1–8) Exploit Simulator

Understand how decoupling XML signature validation from business logic creates critical authentication bypasses. See how an attacker can manipulate XML nodes to authenticate as an administrator.

Mandatory XSW Defenses for Service Providers

  • Schema Validation: Enforce strict XML Schema (XSD) validation to reject unexpected <Extensions> or nested <Assertion> tags.
  • One-Pass ID Pinning: Validate the signature of the EXACT element reference, and pass THAT specific DOM node directly to user extraction. Never run a secondary global XPath like //saml:Assertion/saml:Subject.
  • Reject Multiple Assertions: Reject any SAMLResponse containing more than one <Assertion> unless explicitly expecting multi-assertion encryption wrappers.

Enterprise Identity Protocol Showdown: SAML 2.0 vs OpenID Connect

Direct engineering comparison between legacy enterprise SAML 2.0 and modern OAuth 2.0 / OpenID Connect (OIDC).

Evaluation Dimension SAML 2.0 (OASIS) OpenID Connect (OIDC / OAuth 2.0)
Wire Data Format XML with XML-DSig & XML-Enc JSON with JWS & JWE (JWT)
Token Size Heavy (5 KB – 25 KB) Compact (1 KB – 3 KB)
Single-Page Apps (SPA) Poor (Requires hidden form POST auto-submit) Native (Authorization Code with PKCE)
Mobile App Integration Cumbersome (WebViews, user experience friction) Native (ASWebAuthenticationSession / Custom Tabs)
Discovery Metadata Complex XML EntityDescriptor.xml Simple JSON /.well-known/openid-configuration
Cryptographic Complexity High (C14N canonicalization, XML-DSig bugs) Moderate (Standard JOSE / JWKS key rotation)
API Authorization Not supported (Identity federation only) Built-in via OAuth 2.0 Access & Refresh Tokens
Single Logout (SLO) Supported but fragile (Blocked by 3rd-party cookies) OpenID Back-Channel Logout (Server-to-server)
Primary Adoption Legacy enterprise, government, higher education Modern SaaS, cloud-native apps, mobile apps
Architectural Consensus: For greenfield B2B SaaS applications, support OpenID Connect (OIDC) first. If an enterprise customer requires SAML (e.g. legacy ADFS or strict corporate policy), use an abstraction gateway (like WorkOS, Auth0, or an open-source Keycloak broker) to bridge SAML assertions into clean OIDC tokens so your internal microservices never parse XML.

RFC 7636 PKCE (Proof Key for Code Exchange) S256 Generator

Generate cryptographically secure high-entropy code_verifier values, compute their URL-safe Base64 SHA-256 code_challenge, and construct authorization URLs.

COMPLETE OIDC AUTHORIZATION URL (Send browser here)

Production Service Provider (SP) Code & Metadata Generator

Generate enterprise SAML 2.0 SP EntityDescriptor XML metadata and production backend integration code in Go, Python, and Node.js.

Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement