SAML assertion

A signed XML package of statements that a SAML identity provider issues about a user: that the user authenticated, what attributes the user has, or what the user may access.

In SAML 2.0, an assertion is the XML document an identity provider issues to a service provider to vouch for a user. The OASIS SAML 2.0 core specification defines three kinds of statement it can carry: authentication (the subject authenticated, at a stated time and by a stated method), attribute (facts such as email address or group), and authorisation decision (whether the subject may perform an action on a resource). An assertion also names its issuer and, typically, the subject, its intended audience and a validity window.

The service provider, acting as relying party, trusts the assertion because it is signed with a key the provider already trusts, commonly taken from federation metadata exchanged in advance. It is expected to check the signature, audience and time window, and that the assertion has not been used before. The assertion plays the part the ID token plays in OpenID Connect. An attacker who steals the identity provider’s signing key can forge assertions for any user, the attack commonly called Golden SAML.

Exam relevance: a scenario is likely to ask what the identity provider sends to the service provider after the user authenticates, or why the service provider can trust it. Candidates are expected to answer with a signed assertion, to know its three statement types, and to recall that the user’s password is not part of it.