SAML Flow Simulator
Follow SAML requests, assertions, and logout messages as they move between a user, browser, service provider, and identity provider.
Common
SP-Initiated Single Sign-On
The service provider creates a correlated AuthnRequest; the identity provider returns a signed response through the browser.
Sequence traceEach row is one message
Click a row to inspect its codeMessage / step
UserUser
BrowserBrowser
SPService provider
IdPIdentity provider
Step 1 · Visit app
UserSPRequest a protected page
Complete code sampleFictional wire view
GET /reports SP session: none
Receiver actionRequest a protected page
The user opens the application without an SP session.
Protocol detail and checks
The SP records the intended destination and decides which IdP should authenticate the user.
Preserve a safe return locationDo not accept arbitrary return URLs
End state
The SP creates its own local session only after validating the response and assertion.
Educational model, not a security verdict
Messages are fictional and simplified. A completed trace does not verify a deployment, token, signature, certificate, session, trust relationship, or authorization policy.