ToolsSAML Decoder

    SAML Decoder & Inspector

    Decode and analyze SAML Responses, Requests, and Assertions. Inspect attributes, conditions, signatures, and security properties — 100% client-side.

    🔒 Client-Side Only
    No Data Sent
    SAML 2.0

    Paste SAML Message

    Base64-encoded SAML Response/Request, URL-encoded, or raw XML. Nothing leaves your browser.

    About SAML Security Analysis

    This tool decodes SAML 2.0 messages (Responses, AuthnRequests, LogoutRequests, and standalone Assertions) and checks for common security misconfigurations.

    What We Check

    • XML Signature presence
    • Assertion encryption
    • Time conditions & replay protection
    • Audience restrictions
    • NameID format security
    • Authentication context strength
    • InResponseTo anti-replay

    Supported Formats

    • Base64-encoded SAML (from form POST)
    • URL-encoded + Base64 (from redirect binding)
    • Raw SAML XML
    • SAML 2.0 Responses & Requests
    • Standalone Assertions