SAML 2.0 & OpenID Connect (OIDC) Enterprise Identity Federation Studio
An engineering workbench for enterprise Single Sign-On (SSO): decode Base64 SAML responses, inspect XML-DSig signatures and canonicalization nodes, simulate XML Signature Wrapping (XSW 1–8) exploits, compare SAML vs OIDC protocols, generate cryptographic PKCE challenges, and synthesize production Service Provider integrations.
Interactive SAML 2.0 Assertion & XML-DSig Signature Inspector
Paste a Base64-encoded SAMLResponse or raw XML assertion to decode attributes, verify conditions (NotBefore / NotOnOrAfter), and inspect XML-DSig cryptographic signing references.
| SAML Attribute Name (Friendly / URI) | Claim Value | Enterprise Mapping |
|---|
XML Signature Wrapping (XSW 1–8) Exploit Simulator
Understand how decoupling XML signature validation from business logic creates critical authentication bypasses. See how an attacker can manipulate XML nodes to authenticate as an administrator.
Mandatory XSW Defenses for Service Providers
- Schema Validation: Enforce strict XML Schema (XSD) validation to reject unexpected
<Extensions>or nested<Assertion>tags. - One-Pass ID Pinning: Validate the signature of the EXACT element reference, and pass THAT specific DOM node directly to user extraction. Never run a secondary global XPath like
//saml:Assertion/saml:Subject. - Reject Multiple Assertions: Reject any SAMLResponse containing more than one
<Assertion>unless explicitly expecting multi-assertion encryption wrappers.
Enterprise Identity Protocol Showdown: SAML 2.0 vs OpenID Connect
Direct engineering comparison between legacy enterprise SAML 2.0 and modern OAuth 2.0 / OpenID Connect (OIDC).
| Evaluation Dimension | SAML 2.0 (OASIS) | OpenID Connect (OIDC / OAuth 2.0) |
|---|---|---|
| Wire Data Format | XML with XML-DSig & XML-Enc | JSON with JWS & JWE (JWT) |
| Token Size | Heavy (5 KB – 25 KB) | Compact (1 KB – 3 KB) |
| Single-Page Apps (SPA) | Poor (Requires hidden form POST auto-submit) | Native (Authorization Code with PKCE) |
| Mobile App Integration | Cumbersome (WebViews, user experience friction) | Native (ASWebAuthenticationSession / Custom Tabs) |
| Discovery Metadata | Complex XML EntityDescriptor.xml |
Simple JSON /.well-known/openid-configuration |
| Cryptographic Complexity | High (C14N canonicalization, XML-DSig bugs) | Moderate (Standard JOSE / JWKS key rotation) |
| API Authorization | Not supported (Identity federation only) | Built-in via OAuth 2.0 Access & Refresh Tokens |
| Single Logout (SLO) | Supported but fragile (Blocked by 3rd-party cookies) | OpenID Back-Channel Logout (Server-to-server) |
| Primary Adoption | Legacy enterprise, government, higher education | Modern SaaS, cloud-native apps, mobile apps |
RFC 7636 PKCE (Proof Key for Code Exchange) S256 Generator
Generate cryptographically secure high-entropy code_verifier values, compute their URL-safe Base64 SHA-256 code_challenge, and construct authorization URLs.
Production Service Provider (SP) Code & Metadata Generator
Generate enterprise SAML 2.0 SP EntityDescriptor XML metadata and production backend integration code in Go, Python, and Node.js.