Identity Brief

Issue 01 · 2 October 2026

Flow 03 · Workforce

The assertion comes back through the browser.

SAML 2.0 is still how a lot of workforce SaaS gets its users. The identity provider signs a statement, the browser carries it, and the app has to be picky about who it’s for and how long it’s good.

Watch for

  • In the usual POST binding there’s no server-to-server token call. The browser is the courier.
  • Sign the assertion itself. A signature on the outer response can leave the statement you care about unprotected.
  • Audience, recipient, InResponseTo, and a short clock window are what make that courier acceptable.

Failure modes

  • A validity window of hours. Someone who captured the POST has a working login until it ends.
  • Skipping the audience check because you only have one app today. You’ll have two.
  • Mapping NameID by email without deciding which identity provider you’re willing to believe for that app.