Fake SAML IdP
Relying Party / Service Provider Configuration
Download Metadata XML

Share these parameters with your Relying Party (Service Provider) such as AWS IAM, Okta, Azure AD, Auth0, Google Workspace, or custom SAML applications.

https://fake-saml-idp.pages.dev/
https://fake-saml-idp.pages.dev/logout
https://fake-saml-idp.pages.dev/change-password
https://fake-saml-idp.pages.dev/saml/idp
https://fake-saml-idp.pages.dev/idp-metadata.xml
https://fake-saml-idp.pages.dev/idp-cert.pem
CD:69:12:BD:FF:45:F1:2C:22:B9:00:A9:56:DF:12:49:25:33:F5:64:12:F9:A6:0E:85:4D:67:7D:58:F0:7C:57
Quick Integration Cheatsheets
AWS IAM SAML Provider

Upload idp-metadata.xml when creating an Identity Provider in AWS IAM. Select the AWS IAM preset from the top dropdown for Role and RoleSessionName attributes.

W3C DBSC Testing

Select the W3C DBSC preset or enable the DBSC & Advice section in the SAML Response form to assert device bound public key digests (dbsc:TrustedKey) and certificate fingerprints.

Node / Spring / Passport SAML

Set entryPoint: 'https://fake-saml-idp.pages.dev/', issuer: 'https://fake-saml-idp.pages.dev/saml/idp', and upload or paste the certificate PEM.

Single Logout & Password Reset

If your Service Provider asks for SLO or Change Password URLs, configure https://fake-saml-idp.pages.dev/logout and https://fake-saml-idp.pages.dev/change-password.

Incoming AuthnRequest Inspector

SAML 2.0 Response

Pre-populated with sensible defaults. Configure identity, attributes, DBSC, keys, and submit response to the Service Provider.

1. User Subject & SAML Endpoints
2. SAML Attributes (<saml:AttributeStatement>)
Attribute Name Format Values Action
3. W3C Device Bound Session Credentials (DBSC) & Advice

Assert cryptographic key digests and certificate fingerprints bound to the user's client device per the W3C DBSC specification (xmlns:dbsc="https://www.w3.org/ns/dbsc/saml") formatted as unpadded Base64URL.

4. Cryptographic Keys & Digital Signing

Signatures are generated using standard RSASSA-PKCS1-v1_5 with SHA-256 and W3C Exclusive Canonicalization.

SHA-256 Fingerprint: ...
Signature Targets
5. Signed SAML 2.0 Response Preview & Submit
Target ACS URL: ...
Formatted SAML Response XML
Generating SAML Response...
SAML 2.0 IdP Metadata XML
Open idp-metadata.xml
Loading metadata...