Running on your device · 0 bytes uploaded

# SAML response inspector

Paste a Base64 SAMLResponse or raw XML — assertion fields, attributes, conditions, and signature facts, read locally. Optional signature check against the embedded or pasted key.
SAML responseInspect

- No entity resolution, no external DTD/schema fetch — nothing loads over the network, so no XXE surface and no data leaving.
- No deflated (Redirect-binding) responses: the deflate+base64 form needs DecompressionStream of raw deflate; paste the POST-binding Base64 or XML.
- A verified signature proves the document was not changed since signing — WHO signed it is a certificate-chain question this page cannot answer offline.
- A pasted assertion is a bearer credential — it lives in this tab’s memory for the session, nothing is stored or sent, and a browser tab cannot guarantee the memory is zeroized after you leave.
Nothing in yet

Paste, drop, or type to begin. Everything stays on this device.

paste a SAML response

## Next door in Web

- [Certificate & CSR](/web/certificate)
- [JWK / JWKS](/web/jwk)
[All web tools](/web)

---

Canonical HTML: https://nutter.tools/web/saml
Markdown version: https://nutter.tools/web/saml/index.md
Plain-text version: https://nutter.tools/web/saml/index.txt
Agent index: https://nutter.tools/llms.txt

