$loading...
Decode SAML assertions, detect vulnerabilities, generate signature wrapping payloads, and explore Golden SAML attacks. Supports Base64, URL-encoded, and raw XML input. Covers signature stripping, XSW, XXE injection, audience bypass, and IdP key compromise scenarios. 100% client-side.