Glossary>SAML Consumer Service

SAML Consumer Service

The SAML Consumer Service (Assertion Consumer Service / ACS) is the endpoint at a service provider that receives, validates, and processes SAML assertions from an identity provider to establish an authenticated session.

The SAML 2.0 specification, standardized by OASIS in 2005, defines the ACS endpoint as a required component of every SAML service provider implementation.Over 70% of enterprise single sign-on deployments use SAML 2.0 with ACS endpoints as the primary mechanism for consuming identity provider assertions.The SAML ACS URL is one of the most critical configuration parameters exchanged during SAML metadata sharing between identity providers and service providers.

What is SAML Consumer Service?

SAML Consumer Service (Assertion Consumer Service / ACS) is a core component of the SAML (Security Assertion Markup Language) web single sign-on (SSO) protocol. It is a specific URL endpoint hosted by the service provider (SP) that receives and processes SAML assertions sent from the identity provider (IdP). The ACS is where SAML responses are consumed — hence the name "Consumer Service."

How the ACS fits in SAML SSO. In a typical SP-initiated SAML SSO flow, the user attempts to access a resource on the service provider. The SP generates a SAML authentication request and redirects the user to the IdP. After the user authenticates at the IdP, the IdP constructs a SAML assertion containing identity attributes (username, email, roles) and sends it via HTTP POST or redirect to the SP's ACS URL. The ACS endpoint validates the assertion signature, decrypts it if necessary, extracts the user attributes, and creates a local session for the user.

ACS configuration and security. Every service provider must register its ACS URL(s) with the identity provider as part of SAML metadata exchange. This prevents attackers from sending SAML assertions to unauthorized endpoints. The ACS URL is typically configured alongside the SP's entity ID and certificate. SAML best practices recommend using HTTPS for ACS URLs, validating all SAML assertions against the IdP's public certificate, and enforcing a short assertion validity window (typically 5 minutes) to prevent replay attacks.

Analogy

The SAML Consumer Service is like a secure loading dock at a warehouse. The identity provider is the delivery truck bringing a package (SAML assertion). The ACS is the designated receiving bay with a specific address — only packages delivered to this exact bay are accepted, inspected for authenticity, and processed into the warehouse's inventory (the user's session).

Types and Use Cases

  • Enterprise SaaS SSO: Companies use SAML ACS to enable single sign-on for cloud applications like Salesforce, Workday, and Office 365, allowing employees to access all apps through their corporate identity provider.
  • Federated partner portals: Organizations expose ACS endpoints to enable SSO for external partners and suppliers, granting access to shared portals without managing separate credentials.
  • Government and education federations: Research and education networks (InCommon, eduGAIN) and government identity federations rely on SAML ACS endpoints for cross-organizational identity federation.
  • Custom application integration: Developers building custom SaaS applications implement SAML ACS to support enterprise SSO, allowing their customers to integrate with any SAML 2.0 identity provider.

How it Works

1
User attempts to access a resource on the service provider and is redirected to the identity provider for authentication.
2
User authenticates at the IdP (username/password, MFA, etc.), and the IdP generates a SAML assertion containing user attributes and authentication context.
3
IdP sends the SAML assertion via HTTP POST (or redirect binding) to the pre-registered ACS URL of the service provider.
4
Service provider's ACS endpoint validates the assertion: verifies the digital signature, checks the assertion validity window (NotBefore/NotOnOrAfter), and confirms the audience restriction.
5
Upon successful validation, the SP extracts user attributes from the assertion, creates a local session, and redirects the user to the originally requested resource.
terminal
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
    ID="_8e8dc5f69a6c"
    Version="2.0"
    IssueInstant="2026-06-01T14:30:00Z"
    Destination="https://sp.example.com/saml/acs">
  <saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
      ID="_d71a3e8e"
      IssueInstant="2026-06-01T14:30:00Z">
    <saml:Subject>
      <saml:NameID>user@example.com</saml:NameID>
      <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
        <saml:SubjectConfirmationData
            Recipient="https://sp.example.com/saml/acs"
            NotOnOrAfter="2026-06-01T14:35:00Z"/>
      </saml:SubjectConfirmation>
    </saml:Subject>
    <saml:AttributeStatement>
      <saml:Attribute Name="email">
        <saml:AttributeValue>user@example.com</saml:AttributeValue>
      </saml:Attribute>
    </saml:AttributeStatement>
  </saml:Assertion>
</samlp:Response>

SAML Consumer Service vs SAML Issuer

SAML Consumer Service
SAML Issuer
✓

SAML Consumer Service is the endpoint on the service provider that receives and processes SAML assertions

✗

while SAML Issuer identifies the entity (usually the identity provider) that created and signed the SAML assertion.

✓

The ACS URL must be pre-registered with the IdP and is validated by the ACS endpoint itself

✗

while the SAML Issuer value is embedded in the assertion and is validated by the SP against a trusted list of identity providers.

✓

SAML Consumer Service handles the receiving side of the SAML response (SP-side)

✗

while SAML Issuer handles the sending side (IdP-side) by declaring the source of the assertion.

Best Practices for SAML Consumer Service

  • Register ACS URLs explicitly in your SAML metadata and ensure the IdP only accepts assertions destined for authorized ACS endpoints to prevent open redirector attacks.
  • Validate SAML assertions thoroughly — verify signatures, check NotBefore/NotOnOrAfter timestamps, confirm audience restrictions, and validate recipient attributes against the ACS URL.
  • Use HTTPS exclusively for ACS endpoints to ensure assertions are encrypted in transit and prevent man-in-the-middle interception of SAML tokens.
  • Set short assertion validity windows (3-5 minutes) to limit the window for replay attacks and synchronize clocks between IdP and SP using NTP.

How LoginRadius Powers SAML Consumer Service

LoginRadius supports SAML Consumer Service endpoints as part of its SAML integration framework. When acting as a service provider, LoginRadius provides a dedicated ACS URL that accepts SAML assertions from external identity providers. The platform handles signature validation, attribute mapping, and session creation. When acting as an identity provider, LoginRadius can send SAML assertions to customer-configured ACS endpoints for downstream service providers.

FAQs

Yes. Service providers often register multiple ACS URLs to support different SSO bindings (HTTP POST, HTTP Redirect, Artifact), different user communities, or different environments (production, staging). Each ACS URL must be registered with the IdP in the SAML metadata.

"The ACS URL is the specific endpoint on the SP where SAML assertions are sent — it handles the runtime SAML response reception. The entity ID is a globally unique identifier for the SP itself, used during metadata exchange and assertion audience validation. They serve different purposes: the ACS is operational, the entity ID is identifical."

LoginRadius supports SAML Consumer Service as part of its custom identity provider integration. When configuring a SAML IdP in LoginRadius, administrators specify the ACS URL (also called the LoginRadius SAML endpoint) where the IdP sends SAML assertions. LoginRadius automatically validates assertion signatures, decrypts encrypted assertions, and maps SAML attributes to user profiles.

Customer Identity, Simplified.

No Complexity. No Limits.
Thousands of businesses trust LoginRadius for reliable customer identity. Easy to integrate, effortless to scale.

See how simple identity management can be. Start today!