Skip to content
Security Assertion Markup Language
EntityQ1758048· pop 16· linked from 108 articles

Security Assertion Markup Language

Sign in to save

Also known as SAML

Security Assertion Markup Language (SAML, pronounced SAM-el, ) is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. SAML is an XML-based markup language for security assertions (statements that service providers use to make access-control decisions). SAML is also: A set of XML-based protocol messages A set of protocol message bindings A set of profiles (utilizing all of the above)

Wikidata facts

Show 1 more fact
media type
application/samlmetadata+xml
Sources (1)

via Wikidata · CC0

~19 min read

Article

13 sections
Contents
  • Overview
  • History
  • Versions
  • Design
  • Assertions
  • Protocols
  • Bindings
  • Profiles
  • Security
  • Use
  • See also
  • References
  • External links

Security Assertion Markup Language (SAML, pronounced SAM-el, ) is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. SAML is an XML-based markup language for security assertions (statements that service providers use to make access-control decisions). SAML is also: A set of XML-based protocol messages A set of protocol message bindings A set of profiles (utilizing all of the above)

An important use case that SAML addresses is web-browser single sign-on (SSO). Single sign-on is relatively easy to accomplish within a security domain (using cookies, for example) but extending SSO across security domains is more difficult and resulted in the proliferation of non-interoperable proprietary technologies. The SAML Web Browser SSO profile was specified and standardized to promote interoperability. In practice, SAML SSO is most commonly used for authentication into cloud-based business software.

Gallery (8)

Connections

Categories