Response

SAMLResponse Examples

The SAMLResponse is the message sent by the Identity Provider (IdP) back to the Service Provider (SP) after authenticating the user. It contains assertions about the user’s identity, authentication status, and optionally, authorization attributes.

SAMLResponse Structure

A SAMLResponse typically contains:

  1. Status — indicates whether authentication was successful
  2. Assertion — contains the authenticated user’s attributes
  3. Signature — cryptographic signature for validation
  4. Conditions — validity constraints (time, audience)

Example SAMLResponse

<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                ID="_8e8dc5f69a98cc4c1ff3427e5ce34606fd672f91e6"
                Version="2.0"
                IssueInstant="2014-07-17T01:01:48Z"
                Destination="https://sp.example.com/demo1/index.php?acs"
                InResponseTo="_809707f0030a5d00620c9d9df97f627afe9dcc24">
    <saml:Issuer>https://idp.example.com/metadata.php</saml:Issuer>
    <samlp:Status>
        <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
    </samlp:Status>
    <saml:Assertion xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                    xmlns:xs="http://www.w3.org/2001/XMLSchema"
                    ID="_d71a3a8e9fcc45c9e9d248ef7049393fc8f04e5f75"
                    Version="2.0"
                    IssueInstant="2014-07-17T01:01:48Z">
        <saml:Issuer>https://idp.example.com/metadata.php</saml:Issuer>
        <saml:Subject>
            <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">
                user@example.com
            </saml:NameID>
            <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                <saml:SubjectConfirmationData NotOnOrAfter="2024-01-18T06:21:48Z"
                                              Recipient="https://sp.example.com/demo1/index.php?acs"
                                              InResponseTo="_809707f0030a5d00620c9d9df97f627afe9dcc24"/>
            </saml:SubjectConfirmation>
        </saml:Subject>
        <saml:Conditions NotBefore="2014-07-17T01:01:18Z"
                         NotOnOrAfter="2024-01-18T06:21:48Z">
            <saml:AudienceRestriction>
                <saml:Audience>https://sp.example.com/demo1/metadata.php</saml:Audience>
            </saml:AudienceRestriction>
        </saml:Conditions>
        <saml:AuthnStatement AuthnInstant="2014-07-17T01:01:48Z"
                             SessionNotOnOrAfter="2024-07-17T09:01:48Z"
                             SessionIndex="_be9967abd904ddcae3c0eb4189adbe3f71e327cf93">
            <saml:AuthnContext>
                <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml:AuthnContextClassRef>
            </saml:AuthnContext>
        </saml:AuthnStatement>
        <saml:AttributeStatement>
            <saml:Attribute Name="uid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">test</saml:AttributeValue>
            </saml:Attribute>
            <saml:Attribute Name="mail" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">user@example.com</saml:AttributeValue>
            </saml:Attribute>
        </saml:AttributeStatement>
    </saml:Assertion>
</samlp:Response>

Key Response Elements

ElementDescription
StatusSuccess or failure of authentication
AssertionContains user identity and attributes
InResponseToReferences the original AuthNRequest ID
ConditionsValidity period and audience restrictions
AuthnStatementHow and when the user authenticated
AttributeStatementUser attributes (email, name, roles)

For interactive SAML response validation, visit SAMLTool.com.