SAML Validator — Validate SAML Response Structure Online Free
Validate SAML structure, time conditions, status codes, and required fields — 100% client-side.
Jump to tool ↓Frequently Asked Questions
How SAML Validation Works
A valid SAML assertion must satisfy several structural and temporal conditions before a Service Provider will accept it. Simply decoding the Base64 payload is not enough — the contents must be well-formed XML in the correct SAML namespace, contain the required elements, and fall within the allowed time window.
The most common SAML validation failures in production environments are clock-skew issues, where the IdP and SP server clocks are out of sync by more than the assertion's validity window. Most SAML libraries allow a small tolerance (typically 2–5 minutes) but a skew beyond that will cause consistent authentication failures that look like mysterious rejections to end users.
Other common issues include missing or incorrect AudienceRestriction values (the SP entity ID must match exactly), non-success StatusCode values indicating the IdP rejected the request, missing NameID elements that the SP requires to identify the user, and namespace mismatches between SAML 1.x and SAML 2.0 formats.
This tool runs basic structure and time checks client-side. Paste test SAML (Base64, XML, or URL-encoded) for a debugging report. A passing result is not a signature check or a decision to authenticate the user.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
SAML Assertion vs Response: Structure and Signature Checks
See how a SAML Response wraps an Assertion, where status and identity claims live, and what to check when debugging SSO signatures and audience.
AuthenticationWhat Is SAML and How Does Single Sign-On Work?
SAML is an XML standard that enables single sign-on between identity providers and apps. Learn how SAML works, what a SAML assertion is, and how it compares to OAuth.