Guides authorized security assessment of federated identity flows such as SAML, OIDC and OAuth2 SSO.
- What it does
- This skill provides a workflow for assessing federated identity systems, covering SAML assertion and signature tampering surfaces, OIDC implicit and authorization-code flows with missing PKCE, redirect_uri, state and nonce issues, and IdP/SP metadata or multi-tenant issuer confusion. It walks through mapping the User to SP to IdP to token flow, collecting OpenID configuration and SAML metadata, checking redirect_uri matching, state binding and PKCE, and reviewing session fixation and logout failures. It also lists tooling such as Burp with SAML Raider, jwt_tool and browser DevTools, and points to a companion SSO flow checklist reference.
- When to use it
- Use it for authorized assessment of federated identity and SSO implementations involving SAML, OIDC or OAuth2. It suits testing for SSO misconfiguration, token confusion and protocol flow mismatches, and complements API-focused JWT testing.
- Requirements
- No scripts are shipped; it is instructions only. It assumes authorized scope and test accounts, packet inspection tooling such as Burp with SAML Raider, jwt_tool, browser DevTools, and access to IdP administrative logs, plus the bundled reference checklist.