Running on your device · 0 bytes uploaded SAML response inspector Paste a Base64 SAMLResponse or raw XML — assertion fields, attributes, conditions, and signature facts, read locally. Optional signature check against the embedded or pasted key. SAML responseInspect - No entity resolution, no external DTD/schema fetch — nothing loads over the network, so no XXE surface and no data leaving. - No deflated (Redirect-binding) responses: the deflate+base64 form needs DecompressionStream of raw deflate; paste the POST-binding Base64 or XML. - A verified signature proves the document was not changed since signing — WHO signed it is a certificate-chain question this page cannot answer offline. - A pasted assertion is a bearer credential — it lives in this tab’s memory for the session, nothing is stored or sent, and a browser tab cannot guarantee the memory is zeroized after you leave. Nothing in yet Paste, drop, or type to begin. Everything stays on this device. paste a SAML response Next door in Web - Certificate & CSR (/web/certificate) - JWK / JWKS (/web/jwk) All web tools (/web) Canonical HTML: https://nutter.tools/web/saml Markdown version: https://nutter.tools/web/saml/index.md Plain-text version: https://nutter.tools/web/saml/index.txt Agent index: https://nutter.tools/llms.txt