Visual explanation of SAML authentication (2020)
sheshbabu.com
sheshbabu.com
A Gentle Introduction to SAML - https://news.ycombinator.com/item?id=41036982 - July 2024 (94 comments)
This article covers many of the reasons to avoid SAML: https://workos.com/blog/fun-with-saml-sso-vulnerabilities-an...
Customers usually care most about a specific outcome. If that outcome can be achieved using OIDC instead of SAML, some orgs will go with the recommendation instead of the initial request.
I bring this up because most customers asking for SAML were doing so either because that’s what they were told they needed, or because it’s what they did last time. When presented with additional options and more importantly the rationale behind those options, many customers either switched gears or started working towards OIDC and changed SAML to an intermediate step along the way.
Push for the best solution. Sometimes it doesn’t change anything, but it often does, and even when it doesn’t, it raises awareness of the alternatives.
(There will always be some subset of orgs with immovable standards that are immune to good rationale, but these need not prevent progress elsewhere).
This is a position only people with deep knowledge of SAML can take. Once you understand it, it’s not so bad. But most people - including experienced engineers with decent knowledge of various authentication protocols - find SAML pretty impenetrable, and many of the people implementing it are doing so by following a series of documented procedures that they do not otherwise understand.
Source: was a PM for the authentication stack on a big enterprise platform and helped countless customers with their SAML confusion.
This is a little pedantic since the original article is from 2020 when using SAML might have still been worthwhile to invest time into... But today OpenID Connect (OIDC) is the Enterprise equivalent of these features, or rather these products from major vendors are each just their implementations of OpenID Connect. If you have the choice, you should probably be looking at OIDC instead of SAML for federated identity today.
Any chance you'd share which libraries you used, if any? I'm really trying hard to compile resources that make SAML SSO less of a nightmare, and part of that effort involves tracking down bad documentation.