Is your SAML Response securely signed?

Paste a base64 SAML Response. samlresponse decodes it (raw-DEFLATE inflate supported) and grades the assertion security — is the Assertion signed (not just the Response), SHA-1/MD5 digests, XML Signature Wrapping shapes (multiple assertions, duplicate IDs, NameID comment injection), and the Conditions / Audience / Recipient / SubjectConfirmation windows — against SAML 2.0, OWASP and the XSW CVE class.

Analyzed entirely in your browser — never uploaded. A real SAML Response is a live credential and contains PII, so it is decoded and inspected client-side. Findings reference only structural facts (element presence, counts, algorithm names); your NameID and attribute values are never read into a result, and a saved permalink stores only the derived findings.

Heuristic, not a pentest: structural pattern checks flag suspicious shapes worth investigating. They cannot replicate every SAML library's parser, so a flag is not proof of exploitability, and a clean grade is not proof of safety.

samlresponse

Decode a SAML Response and grade its assertion security

by IntegrAuth