Terminal First Testing With Kane CLI
Natural language browser & mobile app tests right from terminal

TestMu AI's SAML Decoder Base64-decodes a SAML request or response and pretty-prints the XML so you can read the issuer, assertions, attributes, timestamps and signature block. Paste the payload, load the built-in sample, upload a plain-text file, or fetch one from a URL, leave Auto Update on or click Decode, then copy the result or download it. Decoding runs entirely in your browser. Note that DEFLATE-compressed redirect-binding payloads must be inflated before you paste them - this tool only Base64-decodes. This utility is part of the free developer toolkit from TestMu AI (formerly LambdaTest).
SAML (Security Assertion Markup Language) is an open XML‑based standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP), most commonly used to enable Single Sign‑On (SSO) across web applications.
Pair the SAML Decoder with Caesar Cipher Decoder, Base32 Encoder and Decoder, and JWT Decoder when a single conversion is not enough. Check that the encoded output decodes correctly across 3000+ browsers on TestMu AI Real Device Cloud.
A SAML response is an XML document that an identity provider sends to a service provider to assert who the user is. Decoding it reveals the assertion, which is where almost all troubleshooting happens.
Most single sign-on failures come down to a handful of mismatches between the two sides. Decoding the message usually identifies which one applies.
Yes. The decoder is completely free with no signup or subscription, and your payload is decoded in your own browser rather than on a server.
It takes a Base64-encoded SAML request or response, decodes it, and pretty-prints the XML so you can easily inspect assertions, attributes, timestamps, and signatures.
No. All decoding happens client-side in your browser. Nothing is sent to or logged on our servers.
The decoder is version-agnostic: it Base64-decodes and pretty-prints whatever XML the payload contains, so SAML 1.1 and SAML 2.0 assertions and protocol messages such as AuthnRequests and Responses all render the same way. It does not validate against a SAML schema.
You can paste or upload payloads up to 1 MB in size. For larger files, consider splitting them or using our CLI tool.
The tool accepts plain text files containing the Base64 payload (e.g., *.txt, *.xml). You can also paste directly into the input box.
No. Decoding runs entirely in your browser, so the assertion never leaves your machine. That matters because a SAML response is a credential until it expires.
The HTTP-Redirect binding deflates the XML then base64-encodes it to fit in a URL. The HTTP-POST binding usually skips the deflate step, which is why some messages decode directly and others need inflating first.
Did you find this page helpful?
TestMu AI forEnterprise
Get access to solutions built on Enterprise
grade security, privacy, & compliance