Is your SAML Response securely signed?
Paste a base64 SAML Response. samlresponse decodes it (raw-DEFLATE inflate supported) and grades the assertion security — is the Assertion signed (not just the Response), SHA-1/MD5 digests, XML Signature Wrapping shapes (multiple assertions, duplicate IDs, NameID comment injection), and the Conditions / Audience / Recipient / SubjectConfirmation windows — against SAML 2.0, OWASP and the XSW CVE class.
Analyzed entirely in your browser — never uploaded. A real SAML Response is a
live credential and contains PII, so it is decoded and inspected client-side. Findings reference
only structural facts (element presence, counts, algorithm names); your NameID and attribute
values are never read into a result, and a saved permalink stores only the derived findings.
Heuristic, not a pentest: structural pattern checks flag suspicious shapes worth investigating. They cannot replicate every SAML library's parser, so a flag is not proof of exploitability, and a clean grade is not proof of safety.