SAML Decoder
Decode SAML requests and responses from Base64 or HTTP-Redirect payloads
Issuer, audience, ACS, validity, and original XML will appear here.
About this tool
SAML Decoder reads standard or URL-safe Base64, one SAMLRequest/SAMLResponse query parameter, or a complete HTTP(S) redirect URL. It supports SAML 2.0 protocol requests and responses, including AuthnRequest, Response, logout, artifact, query and name-management messages. The XML root must match the parameter name and selected type. It shows the first SAML Issuer, NameID and Conditions plus the listed Audiences, Destination/ACS and XMLDSig element presence. Copy returns the original decoded UTF-8 XML without formatting changes. Input is limited to 1 MB and decoded XML to 2 MB; DOCTYPE and duplicate SAML parameters are rejected. Fields are inspection hints: the tool does not validate the XML schema, signatures, signature references, trust, time acceptance, replay or authorization, and does not decrypt encrypted assertions. NameID text is not trimmed; the summary shows it as a quoted, escaped string so spaces, tabs and newlines remain visible.
Scenario Recipes
Triage an identity-provider redirect failure
Goal: Confirm the binding and protocol fields before changing SSO configuration
- Paste the complete callback URL or captured SAML parameter.
- Confirm message type, Issuer, Destination, Audience, and validity window.
- If those fields match, continue with signature, certificate, clock, replay, and account-mapping checks in the trusted service provider.
Result: A readable SAML XML sample and focused checklist for the next SSO investigation step.
Production Snippets
Inspect a public response without altering NameID
text
Input (Base64):
PHNhbWxwOlJlc3BvbnNlIHhtbG5zOnNhbWxwPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6cHJvdG9jb2wiIHhtbG5zOnNhbWw9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDphc3NlcnRpb24iPjxzYW1sOklzc3Vlcj5odHRwczovL2lkcC5leGFtcGxlPC9zYW1sOklzc3Vlcj48c2FtbDpBc3NlcnRpb24+PHNhbWw6U3ViamVjdD48c2FtbDpOYW1lSUQ+YWxpY2U8L3NhbWw6TmFtZUlEPjwvc2FtbDpTdWJqZWN0Pjwvc2FtbDpBc3NlcnRpb24+PC9zYW1scDpSZXNwb25zZT4=
Expected: Response; Issuer https://idp.example; Subject alice; signature not detected.
Copy original XML preserves NameID text exactly. A SAMLRequest parameter around this value must fail.Frequently Asked Questions
Which inputs can I paste?
Paste Base64, a query string such as SAMLResponse=...&RelayState=..., or a full HTTP(S) URL. Exactly one case-sensitive SAMLRequest or SAMLResponse parameter is required. Percent-encode Base64 + as %2B when sharing URLs; literal + is also preserved for copied parameters.
Does Base64 decoding prove the HTTP binding?
No. Base64 XML does not establish how the message was transported. Raw DEFLATE is reported only when decompression actually occurred; Redirect query signatures are not verified.
Can it verify an XML signature?
No. It detects elements in the XMLDSig namespace. It does not verify signature values, reference digests, canonicalization, certificate trust or which claims were signed.
Why does copied XML keep its original whitespace?
Adding indentation can change element text or signed bytes. Copy preserves the decoded XML text; do not treat a decoded capture as a reusable authenticated login message.
Why can decoded SAML still fail login?
The service provider separately checks schema, signatures, Audience, Destination, Recipient, timestamps, InResponseTo, replay protection and account mapping. The summary shows only the first matching NameID and Conditions when multiple assertions exist.
Are encrypted assertions decrypted?
No. Decryption requires the service provider private key and belongs in the trusted identity system.
What size and XML limits apply?
Input is limited to 1 MB and decompressed UTF-8 XML to 2 MB. Unsupported namespaces or roots, DOCTYPE, malformed encodings, duplicate SAML parameters and conflicting message types are rejected.
Is the payload uploaded or saved as a draft?
No. Decoding and XML inspection happen locally; the tool does not persist a payload draft. Analytics use fixed message and encoding categories, not the XML, NameID or Issuer.
Keep browsing