SAML Assertion and Signature Validator

SAML Assertion and Signature Validator

Review SAML structure, correlation, audiences, recipients, and time windows without claiming XML-signature trust.

Signature presence is reported separately from cryptographic verification. A passing structural review is not authorization or proof of deployment acceptance.

XML values are parsed locally; no destination or issuer URL is opened.
SAML Response / AssertionXML · structural review
warningsaml.signature_missing · $.signature · No XML Signature element was supplied.
StatusReviewable
AssertionPresent
Signaturemissing
Findings1
Validation reviewStructural evidence only
{
  "status": "reviewable",
  "summary": {
    "root": "samlp:Response",
    "issuer": "https://idp.example.test",
    "audience": "https://app.example.test",
    "recipient": "https://app.example.test/saml/acs",
    "destination": "https://app.example.test/saml/acs",
    "inResponseTo": "_req_1001",
    "assertionPresent": true,
    "signature": "missing",
    "timeWindow": {
      "notBefore": "2026-01-01T00:00:00Z",
      "notOnOrAfter": "2099-01-01T00:00:00Z"
    }
  },
  "issues": [
    {
      "code": "saml.signature_missing",
      "level": "warning",
      "path": "$.signature",
      "message": "No XML Signature element was supplied."
    }
  ]
}