SAML 2.0 SP-Initiated SSO
A service provider redirects the user to an identity provider, which posts back a signed SAML assertion to establish a session.
In SP-initiated single sign-on, the user starts at the service provider. The SP builds an AuthnRequest, redirects the browser to the IdP, and the IdP returns a signed SAML Response containing an authentication assertion via an auto-submitted HTML form post.