SAML (Security Assertion Markup Language)
Security Assertion Markup Language (SAML) is an established, XML-based standard for the secure exchange of authentication and authorization data between an identity provider and applications (service providers).
After a successful login, the identity provider issues a digitally signed assertion, which the service provider verifies and accepts as proof of identity. The flow can be initiated by the service (SP-initiated) or by the identity provider (IdP-initiated). On this basis, numerous applications can be connected without individual adaptations – SAML has therefore been the supporting technology for enterprise single sign-on and federated logins between organizations for years.
Compared with the more modern OpenID Connect, SAML is considered more heavyweight and less suitable for mobile apps and APIs, but it remains widespread in classic enterprise and government environments. In practice, both standards coexist: new, API-oriented applications mostly rely on OIDC, while legacy systems remain connected via SAML.