SAML Flow Simulator

SAML Flow Simulator

Follow SAML requests, assertions, and logout messages as they move between a user, browser, service provider, and identity provider.

Interactive protocol lesson

Profiles and bindings combine into several flows; four are simulated here.

Follow the message row, then inspect the code received by the next actor.

4 scenarios
Common

SP-Initiated Single Sign-On

The service provider creates a correlated AuthnRequest; the identity provider returns a signed response through the browser.

Step 1 of 8Show the risk and defensive control for the selected protocol message.
Sequence traceEach row is one message
Click a row to inspect its code
Message / step
UserUser
BrowserBrowser
SPService provider
IdPIdentity provider
Step 1 · Visit app

Request a protected page

UserSP
Complete code sampleFictional wire view
GET /reports
SP session: none
Receiver actionRequest a protected page

The user opens the application without an SP session.

Protocol detail and checks

The SP records the intended destination and decides which IdP should authenticate the user.

Preserve a safe return locationDo not accept arbitrary return URLs
End state

The SP creates its own local session only after validating the response and assertion.

Educational model, not a security verdict

Messages are fictional and simplified. A completed trace does not verify a deployment, token, signature, certificate, session, trust relationship, or authorization policy.