Process SAML authentication request using HTTP Redirect binding. The application policy or ForceAuthn can require fresh authentication; otherwise an existing session may be reused. The response assertion preserves the actual authentication time. When authnRequestConfig.requireSignedAuthnRequests is true, the request must be signed using the configured service provider signing certificate.
GET
/api/saml/{id}/authn
curl \
--request GET 'https://[tenant_id].logto.app/api/saml/{id}/authn?SAMLRequest=string' \
--header "Authorization: Bearer $ACCESS_TOKEN"