SAMLResponse is an XML message sent from the Identity Provider to the Service Provider after user authentication. It contains one or more assertions with the user's identity information and is typically sent via HTTP POST to the SP's Assertion Consumer Service (ACS) URL.
<samlp:Response
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
ID="_response123"
Version="2.0"
IssueInstant="2024-01-15T10:30:00Z"
Destination="https://sp.example.com/acs"
InResponseTo="_request456">
<saml:Issuer>https://idp.example.com</saml:Issuer>
<ds:Signature>...</ds:Signature>
<samlp:Status>
<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</samlp:Status>
<saml:Assertion>
<!-- Signed assertion with user info -->
</saml:Assertion>
</samlp:Response>
// HTTP-POST to ACS URL
POST /saml/acs
Content-Type: application/x-www-form-urlencoded
SAMLResponse=PHNhbWxwOlJlc3BvbnNl...&RelayState=/dashboard