SAML Response Decoder
Decode a base64 SAML response or request, inflate a redirect binding payload, and inspect the issuer, conditions, attributes, signature location and timestamp validity.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
The assertion is where single sign-on succeeds or fails
A SAML response is XML wrapped in base64, and for the redirect binding it is deflate compressed first and URL encoded on top of that. When federation between an identity provider and a service provider fails, the error message is almost always generic while the actual cause sits in the assertion: a mismatched audience, an expired condition window, a name identifier format the service provider does not accept, or an attribute the application expects under a different name. Reading the decoded XML answers in seconds what a support ticket takes days to resolve.
The conditions element is the usual culprit
Assertions carry a NotBefore and NotOnOrAfter pair that is typically only a few minutes wide, and an AudienceRestriction naming the service provider entity ID. Clock skew of more than a few minutes between the two systems causes intermittent failures that look random. An audience value that differs from the service provider entity ID by a trailing slash or a scheme fails every time. Both are visible immediately in the decoded assertion and invisible in any log message.
Decoding proves nothing about validity
Anyone can decode a SAML response, which is exactly why the signature exists. Verifying it requires the identity provider's certificate and correct canonicalisation, and it must be performed by the service provider library rather than by eye. This tool shows where the signature sits, what it covers and which algorithms were used, all of which matter, but it cannot and does not tell you the assertion is authentic.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Why is my SAML response not just base64?
The HTTP redirect binding deflate compresses the XML before base64 encoding it and then URL encodes the result. The POST binding uses plain base64. This tool detects which and handles both.
What causes "invalid audience" errors?
The AudienceRestriction in the assertion does not exactly match the service provider entity ID configured at the identity provider. Trailing slashes, http versus https and case differences all cause it, and the values look identical at a glance.
Why do logins fail intermittently?
Almost always clock skew. The conditions window is typically five minutes, so a server drifting by more than that fails some requests and not others. Check NTP synchronisation on both ends before looking anywhere else.
Does decoding verify the signature?
No, and nothing that decodes in a browser could. Verification needs the identity provider certificate and correct XML canonicalisation, and it must happen in your service provider library. This shows where the signature is and what it covers, not whether it is valid.
Is it safe to paste a real SAML response here?
Decoding runs entirely in your browser and nothing is transmitted. That said, a SAML response is a live credential until it expires or is consumed, so treat it as a secret and prefer a test assertion where you can.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste a SAMLResponse, SAMLRequest or raw XML to decode and inspect it.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.