SAML 2.0 SP-Initiated SSO

A service provider redirects the user to an identity provider, which posts back a signed SAML assertion to establish a session.

User Login & SSO

In SP-initiated single sign-on, the user starts at the service provider. The SP builds an AuthnRequest, redirects the browser to the IdP, and the IdP returns a signed SAML Response containing an authentication assertion via an auto-submitted HTML form post.

Identity ProviderService ProviderBrowserUserIdentity ProviderService ProviderBrowserUserNavigate to SP resource1GET /protected2302 to IdP SSO endpoint3GET /saml4Login prompt5Credentials6Form POST response7POST /saml/acs8Validate signature, conditions, audience, etc.9Set authenticated session10GET /protected (cookie)11200 OK - Protected resource12

Official Specifications

Additional Resources

Back to all diagrams