Skip to main content

Side by side

SAMLvsOpenID Connect

What is the difference between SAML and OpenID Connect?

Updated 3 min read8 differences

In short

Both provide single sign-on. SAML sends signed XML assertions through the browser; OpenID Connect builds on OAuth 2.0 and issues a signed JSON ID token.

SAML

Security Assertion Markup Language

SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.

Read the page on SAML

OpenID Connect

OIDC

OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.

Read the page on OpenID Connect

SAML and OpenID Connect compared

AspectSAMLOpenID Connect
Published2005 (SAML 2.0), by OASIS2014, by the OpenID Foundation
FormatXML assertions with XML SignatureJSON, with the ID token as a signed JWT
Built onIts own XML-based protocolOAuth 2.0
Typical flowThe browser posts a signed assertion to the appThe app exchanges a one-time code for tokens
API accessNot part of it: it handles loginThe same exchange can return an OAuth access token
Mobile and single-page appsAwkward: built around browser redirects and form postsWell suited, with the code flow and PKCE
SetupExchange metadata and certificates with each IdPRead the provider's discovery document and keys from a URL
Common inEnterprise single sign-on for employeesNew apps, consumer logins and enterprise single sign-on

The difference, explained

SAML 2.0, published in 2005, and OpenID Connect, finalized in 2014, solve the same core problem: letting users sign in to an application through an identity provider (IdP), such as Microsoft Entra ID, Okta or Google, instead of a separate password. After the IdP authenticates the user, it vouches for them to the application with a signed statement of who they are.

The difference is in the format and the plumbing. SAML packages that statement as an XML assertion, signed with XML Signature, and usually posts it to the application through the browser. OpenID Connect is a layer on top of OAuth 2.0: the app receives a one-time code, exchanges it with the provider for tokens, and checks the ID token, a JSON Web Token with claims such as the user's ID and email. Because it is built on OAuth, the same exchange can also give the app an access token for calling APIs.

That makes OpenID Connect a better fit for mobile apps, single-page apps and APIs, and the usual choice for new applications and for consumer logins such as "Sign in with Google". SAML remains deeply rooted in enterprises: many companies require it for workforce single sign-on, so software sold to them often supports both. Most identity providers speak both protocols.

A common misconception is that SAML is insecure and OpenID Connect is safe by default. Both are secure when implemented with care, and both fail when signatures and claims aren't checked: SAML's XML signatures are notoriously tricky to validate, and an ID token must be verified for its issuer, audience and expiry. In either case, use a well-maintained library rather than writing your own.

Which one should you use?

Choose SAML when…

  • Enterprise customers require SAML for their single sign-on.
  • You integrate with older apps or identity systems that only speak SAML.
  • Your app is a classic server-rendered web app used through a browser.

Choose OpenID Connect when…

  • You build a new application, especially a mobile or single-page app.
  • Users should sign in with providers such as Google, Apple or Microsoft.
  • The app also needs access tokens to call APIs for the user.

What the app receives: a SAML assertion and an ID token

SAMLtext
<!-- SAML: part of the signed XML assertion the IdP posts back -->
<saml:Assertion ID="_a75adf55" IssueInstant="2026-10-06T09:30:00Z">
  <saml:Issuer>https://idp.example.com</saml:Issuer>
  <ds:Signature>…</ds:Signature>
  <saml:Subject>
    <saml:NameID>ada@example.com</saml:NameID>
  </saml:Subject>
  <saml:Conditions NotOnOrAfter="2026-10-06T09:35:00Z">
    <saml:AudienceRestriction>…https://app.example.com…</saml:AudienceRestriction>
  </saml:Conditions>
  <saml:AttributeStatement>…</saml:AttributeStatement>
</saml:Assertion>
OpenID Connecttext
// OpenID Connect: the decoded payload of the signed ID token (a JWT)
{
  "iss": "https://idp.example.com",
  "sub": "248289761001",
  "aud": "app-client-id",
  "email": "ada@example.com",
  "iat": 1791279000,
  "exp": 1791279300,
  "nonce": "n-0S6_WzA2Mj"
}

Readers ask

Is SAML being replaced by OpenID Connect?

For new applications, largely yes. But SAML is so widely deployed in enterprises that it will remain a requirement for many years, so business software often supports both.

Can an app support both SAML and OpenID Connect?

Yes, and many do, often through an identity broker that speaks both protocols and gives the app one consistent way to sign users in.

Is OpenID Connect the same as OAuth?

No. OAuth 2.0 grants apps access to APIs; OpenID Connect builds on it to add login, with an ID token that says who the user is.

More

Settings