Glossary

SAML

Acronym
Also known as: security-assertion-markup-language, saml-2.0
TechSecurityAuth

Definition

Security Assertion Markup Language — the XML standard (OASIS, 2.0 since 2005) for single sign-on between an identity provider and a service provider: the provider signs an assertion saying who the user is and what attributes they carry, the browser posts it to the application, and the application verifies the signature and starts a session

The enterprise's SSO. Okta, Entra ID, Ping and the like speak it to the applications a company buys, which is why a B2B product's pricing page has an 'SSO' tier and why that tier means SAML. The assertion is XML and signed, the exchange is browser redirects and form posts, and the metadata (certificates, endpoints, entity IDs) is swapped once at setup. It predates OAuth, solves a narrower problem — authentication, not delegated API access — and is being overtaken by OpenID Connect where a product can choose.

Tech

Heavy, and trusted for the same reason. A SAML integration is a day of certificate and metadata exchange with a customer's IT department, and the day is the point: the enterprise wants the identity relationship to be a configured, auditable thing.

Related Terms

  • a: Appearance
  • ?: Keyboard shortcuts