SAML Consumer Service
The SAML Consumer Service (Assertion Consumer Service / ACS) is the endpoint at a service provider that receives, validates, and processes SAML assertions from an identity provider to establish an authenticated session.
What is SAML Consumer Service?
SAML Consumer Service (Assertion Consumer Service / ACS) is a core component of the SAML (Security Assertion Markup Language) web single sign-on (SSO) protocol. It is a specific URL endpoint hosted by the service provider (SP) that receives and processes SAML assertions sent from the identity provider (IdP). The ACS is where SAML responses are consumed — hence the name "Consumer Service."
How the ACS fits in SAML SSO. In a typical SP-initiated SAML SSO flow, the user attempts to access a resource on the service provider. The SP generates a SAML authentication request and redirects the user to the IdP. After the user authenticates at the IdP, the IdP constructs a SAML assertion containing identity attributes (username, email, roles) and sends it via HTTP POST or redirect to the SP's ACS URL. The ACS endpoint validates the assertion signature, decrypts it if necessary, extracts the user attributes, and creates a local session for the user.
ACS configuration and security. Every service provider must register its ACS URL(s) with the identity provider as part of SAML metadata exchange. This prevents attackers from sending SAML assertions to unauthorized endpoints. The ACS URL is typically configured alongside the SP's entity ID and certificate. SAML best practices recommend using HTTPS for ACS URLs, validating all SAML assertions against the IdP's public certificate, and enforcing a short assertion validity window (typically 5 minutes) to prevent replay attacks.
Analogy
The SAML Consumer Service is like a secure loading dock at a warehouse. The identity provider is the delivery truck bringing a package (SAML assertion). The ACS is the designated receiving bay with a specific address — only packages delivered to this exact bay are accepted, inspected for authenticity, and processed into the warehouse's inventory (the user's session).
Types and Use Cases
- Enterprise SaaS SSO: Companies use SAML ACS to enable single sign-on for cloud applications like Salesforce, Workday, and Office 365, allowing employees to access all apps through their corporate identity provider.
- Federated partner portals: Organizations expose ACS endpoints to enable SSO for external partners and suppliers, granting access to shared portals without managing separate credentials.
- Government and education federations: Research and education networks (InCommon, eduGAIN) and government identity federations rely on SAML ACS endpoints for cross-organizational identity federation.
- Custom application integration: Developers building custom SaaS applications implement SAML ACS to support enterprise SSO, allowing their customers to integrate with any SAML 2.0 identity provider.
How it Works
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
ID="_8e8dc5f69a6c"
Version="2.0"
IssueInstant="2026-06-01T14:30:00Z"
Destination="https://sp.example.com/saml/acs">
<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_d71a3e8e"
IssueInstant="2026-06-01T14:30:00Z">
<saml:Subject>
<saml:NameID>user@example.com</saml:NameID>
<saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml:SubjectConfirmationData
Recipient="https://sp.example.com/saml/acs"
NotOnOrAfter="2026-06-01T14:35:00Z"/>
</saml:SubjectConfirmation>
</saml:Subject>
<saml:AttributeStatement>
<saml:Attribute Name="email">
<saml:AttributeValue>user@example.com</saml:AttributeValue>
</saml:Attribute>
</saml:AttributeStatement>
</saml:Assertion>
</samlp:Response>SAML Consumer Service vs SAML Issuer
SAML Consumer Service
SAML Issuer
SAML Consumer Service is the endpoint on the service provider that receives and processes SAML assertions
while SAML Issuer identifies the entity (usually the identity provider) that created and signed the SAML assertion.
The ACS URL must be pre-registered with the IdP and is validated by the ACS endpoint itself
while the SAML Issuer value is embedded in the assertion and is validated by the SP against a trusted list of identity providers.
SAML Consumer Service handles the receiving side of the SAML response (SP-side)
while SAML Issuer handles the sending side (IdP-side) by declaring the source of the assertion.
Best Practices for SAML Consumer Service
- Register ACS URLs explicitly in your SAML metadata and ensure the IdP only accepts assertions destined for authorized ACS endpoints to prevent open redirector attacks.
- Validate SAML assertions thoroughly — verify signatures, check NotBefore/NotOnOrAfter timestamps, confirm audience restrictions, and validate recipient attributes against the ACS URL.
- Use HTTPS exclusively for ACS endpoints to ensure assertions are encrypted in transit and prevent man-in-the-middle interception of SAML tokens.
- Set short assertion validity windows (3-5 minutes) to limit the window for replay attacks and synchronize clocks between IdP and SP using NTP.
How LoginRadius Powers SAML Consumer Service
LoginRadius supports SAML Consumer Service endpoints as part of its SAML integration framework. When acting as a service provider, LoginRadius provides a dedicated ACS URL that accepts SAML assertions from external identity providers. The platform handles signature validation, attribute mapping, and session creation. When acting as an identity provider, LoginRadius can send SAML assertions to customer-configured ACS endpoints for downstream service providers.
FAQs
Yes. Service providers often register multiple ACS URLs to support different SSO bindings (HTTP POST, HTTP Redirect, Artifact), different user communities, or different environments (production, staging). Each ACS URL must be registered with the IdP in the SAML metadata.
"The ACS URL is the specific endpoint on the SP where SAML assertions are sent — it handles the runtime SAML response reception. The entity ID is a globally unique identifier for the SP itself, used during metadata exchange and assertion audience validation. They serve different purposes: the ACS is operational, the entity ID is identifical."
LoginRadius supports SAML Consumer Service as part of its custom identity provider integration. When configuring a SAML IdP in LoginRadius, administrators specify the ACS URL (also called the LoginRadius SAML endpoint) where the IdP sends SAML assertions. LoginRadius automatically validates assertion signatures, decrypts encrypted assertions, and maps SAML attributes to user profiles.