Side by side
SAMLvsOpenID Connect
What is the difference between SAML and OpenID Connect?
Updated 3 min read8 differences
In short
Both provide single sign-on. SAML sends signed XML assertions through the browser; OpenID Connect builds on OAuth 2.0 and issues a signed JSON ID token.
SAML
Security Assertion Markup Language
SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
Read the page on SAMLOpenID Connect
OIDC
OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
Read the page on OpenID ConnectSAML and OpenID Connect compared
| Aspect | SAML | OpenID Connect |
|---|---|---|
| Published | 2005 (SAML 2.0), by OASIS | 2014, by the OpenID Foundation |
| Format | XML assertions with XML Signature | JSON, with the ID token as a signed JWT |
| Built on | Its own XML-based protocol | OAuth 2.0 |
| Typical flow | The browser posts a signed assertion to the app | The app exchanges a one-time code for tokens |
| API access | Not part of it: it handles login | The same exchange can return an OAuth access token |
| Mobile and single-page apps | Awkward: built around browser redirects and form posts | Well suited, with the code flow and PKCE |
| Setup | Exchange metadata and certificates with each IdP | Read the provider's discovery document and keys from a URL |
| Common in | Enterprise single sign-on for employees | New apps, consumer logins and enterprise single sign-on |
The difference, explained
SAML 2.0, published in 2005, and OpenID Connect, finalized in 2014, solve the same core problem: letting users sign in to an application through an identity provider (IdP), such as Microsoft Entra ID, Okta or Google, instead of a separate password. After the IdP authenticates the user, it vouches for them to the application with a signed statement of who they are.
The difference is in the format and the plumbing. SAML packages that statement as an XML assertion, signed with XML Signature, and usually posts it to the application through the browser. OpenID Connect is a layer on top of OAuth 2.0: the app receives a one-time code, exchanges it with the provider for tokens, and checks the ID token, a JSON Web Token with claims such as the user's ID and email. Because it is built on OAuth, the same exchange can also give the app an access token for calling APIs.
That makes OpenID Connect a better fit for mobile apps, single-page apps and APIs, and the usual choice for new applications and for consumer logins such as "Sign in with Google". SAML remains deeply rooted in enterprises: many companies require it for workforce single sign-on, so software sold to them often supports both. Most identity providers speak both protocols.
A common misconception is that SAML is insecure and OpenID Connect is safe by default. Both are secure when implemented with care, and both fail when signatures and claims aren't checked: SAML's XML signatures are notoriously tricky to validate, and an ID token must be verified for its issuer, audience and expiry. In either case, use a well-maintained library rather than writing your own.
Which one should you use?
Choose SAML when…
- Enterprise customers require SAML for their single sign-on.
- You integrate with older apps or identity systems that only speak SAML.
- Your app is a classic server-rendered web app used through a browser.
Choose OpenID Connect when…
- You build a new application, especially a mobile or single-page app.
- Users should sign in with providers such as Google, Apple or Microsoft.
- The app also needs access tokens to call APIs for the user.
What the app receives: a SAML assertion and an ID token
<!-- SAML: part of the signed XML assertion the IdP posts back -->
<saml:Assertion ID="_a75adf55" IssueInstant="2026-10-06T09:30:00Z">
<saml:Issuer>https://idp.example.com</saml:Issuer>
<ds:Signature>…</ds:Signature>
<saml:Subject>
<saml:NameID>ada@example.com</saml:NameID>
</saml:Subject>
<saml:Conditions NotOnOrAfter="2026-10-06T09:35:00Z">
<saml:AudienceRestriction>…https://app.example.com…</saml:AudienceRestriction>
</saml:Conditions>
<saml:AttributeStatement>…</saml:AttributeStatement>
</saml:Assertion>// OpenID Connect: the decoded payload of the signed ID token (a JWT)
{
"iss": "https://idp.example.com",
"sub": "248289761001",
"aud": "app-client-id",
"email": "ada@example.com",
"iat": 1791279000,
"exp": 1791279300,
"nonce": "n-0S6_WzA2Mj"
}Readers ask
Is SAML being replaced by OpenID Connect?
For new applications, largely yes. But SAML is so widely deployed in enterprises that it will remain a requirement for many years, so business software often supports both.
Can an app support both SAML and OpenID Connect?
Yes, and many do, often through an identity broker that speaks both protocols and gives the app one consistent way to sign users in.