Security Assertion Markup Language — an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). The longstanding standard for enterprise SSO.
SAML predates OAuth/OIDC and remains dominant in enterprise SSO, especially in industries with long-running enterprise software portfolios. The flow: SP (app) generates a SAML request → user redirects to IdP → IdP authenticates and signs a SAML assertion → assertion POSTed back to SP → SP verifies signature and creates session. SAML is more complex than OIDC (XML signatures, multiple binding modes) but enjoys broader enterprise tool support.
Integrating an enterprise app with Okta as the SAML IdP — IT admins configure the trust relationship once; users get seamless SSO.
SAML remains the enterprise default for SSO; OIDC is winning in new applications. Most companies need both protocols in their identity stack.
Need help implementing this in your business?
Get Started