Security Assertion Markup Language (SAML)
An OASIS XML standard for passing signed authentication and attribute assertions from an identity provider to a service provider, widely used for web single sign-on.
SAML is an open standard from OASIS, and version 2.0, approved in 2005, is the version in general use. It defines how an identity provider (IdP) passes signed assertions about a user to a service provider (SP), so the user can reach the SP’s application without separate credentials for it. The standard is organised into assertions (what is said), protocols (request and response messages), bindings (how messages travel, such as by HTTP redirect or form post) and profiles (how the parts combine, the best known being Web Browser SSO).
In the common flow, the user visits the SP, is redirected to the IdP, authenticates there, and returns with an assertion that the SP validates against the IdP’s signing certificate before creating its own session. SAML is a major route to federated identity and cross-organisation single sign-on. It differs from OAuth, which delegates authorisation and is not by itself authentication, and from OpenID Connect, which adds authentication on top of OAuth using JSON tokens.
Exam relevance: a scenario in which a partner or cloud application accepts corporate sign-ins through signed XML assertions is likely to point to SAML. Candidates are expected to know its three parties (the user, the IdP and the SP) and to keep SAML, OAuth and OpenID Connect apart by what each one carries.