Hero Background

Terminal First Testing With Kane CLI

Natural language browser & mobile app tests right from terminal

Terminal First Testing With Kane CLI

SAML Decoder

TestMu AI's SAML Decoder Base64-decodes a SAML request or response and pretty-prints the XML so you can read the issuer, assertions, attributes, timestamps and signature block. Paste the payload, load the built-in sample, upload a plain-text file, or fetch one from a URL, leave Auto Update on or click Decode, then copy the result or download it. Decoding runs entirely in your browser. Note that DEFLATE-compressed redirect-binding payloads must be inflated before you paste them - this tool only Base64-decodes. This utility is part of the free developer toolkit from TestMu AI (formerly LambdaTest).

Categories

...

Verify Before You Deploy

Terminal-native web and mobile automation.

Try Kane CLI
...

Write Tests in Plain English with KaneAI

Create, debug, and evolve tests using natural language.

Try for free
...

3000+ Browsers. One Platform.

See exactly how your site performs everywhere.

Try it free
Input
Output

What is SAML?

SAML (Security Assertion Markup Language) is an open XML‑based standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP), most commonly used to enable Single Sign‑On (SSO) across web applications.

  • Identity Provider (IdP): Authenticates users and issues signed SAML assertions.
  • Service Provider (SP): Consumes those assertions to grant user access.
  • SAML Assertion: An XML document containing authentication statements (who, when), user attributes (e.g., email, roles) and optional authorization decisions.

How to Use this SAML Decoder

  • Enter or Load Your SAML Payload
    • Copy/Paste: Pull in from your clipboard
    • Upload: Import a .txt/.xml file
    • Fetch: Load directly from a URL
  • Toggle Auto-Update
    • With Auto Update checked, every change you make will immediately re-decode
    • Uncheck it if you’d rather manually trigger decoding.
  • Decode
    • If Auto-Update is unchecked, click the central Decode button to run the decoder.
    • The tool will Base64-decode your input and pretty-print the resulting XML.
  • Review the Output: Your decoded, formatted XML appears in the Output pane.
    • Copy the XML to your clipboard
    • Download it as an .xml or .txt file
Kane CLI - Testing Agent in Your Terminal

What are the use cases of this SAML Request Decoder?

  • Debug SSO issues: Inspect SAML requests to find errors or misconfigurations.
  • Test integrations: Validate setup between identity provider (IdP) and service provider (SP).
  • Check security: Review signatures, encryption, and authentication contexts.
  • View readable XML: Decode base64/XML to see the actual request content.
  • Iterate quickly: Tweak the Base64 in the input box and re-decode instantly with Auto Update on. Re-encoding edited XML needs a separate Base64 encoder.
  • Learn & teach: Use in tutorials or training to explain SAML request structure.

Pair the SAML Decoder with Caesar Cipher Decoder, Base32 Encoder and Decoder, and JWT Decoder when a single conversion is not enough. Check that the encoded output decodes correctly across 3000+ browsers on TestMu AI Real Device Cloud.

What a SAML message contains

A SAML response is an XML document that an identity provider sends to a service provider to assert who the user is. Decoding it reveals the assertion, which is where almost all troubleshooting happens.

  • Issuer: which identity provider produced the assertion.
  • Subject: the NameID identifying the authenticated user.
  • Conditions: the NotBefore and NotOnOrAfter window during which the assertion is valid.
  • AttributeStatement: the claims passed to the application, such as email, groups or roles.
  • Signature: the XML signature the service provider verifies before trusting anything above.

Common SAML errors and what they point to

Most single sign-on failures come down to a handful of mismatches between the two sides. Decoding the message usually identifies which one applies.

  • Clock skew: an assertion rejected as expired often means the two servers differ by more than the allowed drift.
  • Audience mismatch: the AudienceRestriction must match the service provider entity ID exactly, including scheme and trailing slash.
  • Wrong NameID format: the application expects an email address but receives a persistent identifier, or the reverse.
  • Missing attributes: role or group claims not released by the identity provider show up as an empty AttributeStatement.
  • Signature failure: the certificate configured at the service provider no longer matches the one signing the assertion.

Frequently Asked Questions (FAQs)

Is this SAML decoder free?

Yes. The decoder is completely free with no signup or subscription, and your payload is decoded in your own browser rather than on a server.

What does this SAML Decoder do?

It takes a Base64-encoded SAML request or response, decodes it, and pretty-prints the XML so you can easily inspect assertions, attributes, timestamps, and signatures.

Is my SAML data stored on your servers?

No. All decoding happens client-side in your browser. Nothing is sent to or logged on our servers.

Which SAML versions are supported?

The decoder is version-agnostic: it Base64-decodes and pretty-prints whatever XML the payload contains, so SAML 1.1 and SAML 2.0 assertions and protocol messages such as AuthnRequests and Responses all render the same way. It does not validate against a SAML schema.

How large of a payload can I decode?

You can paste or upload payloads up to 1 MB in size. For larger files, consider splitting them or using our CLI tool.

What file formats can I upload?

The tool accepts plain text files containing the Base64 payload (e.g., *.txt, *.xml). You can also paste directly into the input box.

Is my SAML response sent anywhere when I decode it?

No. Decoding runs entirely in your browser, so the assertion never leaves your machine. That matters because a SAML response is a credential until it expires.

Why is my SAML assertion base64 and deflated?

The HTTP-Redirect binding deflates the XML then base64-encodes it to fit in a URL. The HTTP-POST binding usually skips the deflate step, which is why some messages decode directly and others need inflating first.

KaneAI - GenAI-Native Testing Agent

Did you find this page helpful?

TestMu AI forEnterprise

Get access to solutions built on Enterprise
grade security, privacy, & compliance

  • Advanced access controls
  • Advanced data retention rules
  • Advanced Local Testing
  • Premium Support options
  • Early access to beta features
  • Private Slack Channel
  • Unlimited Manual Accessibility DevTools Tests