Process SAML authentication request using HTTP POST binding. The application policy or ForceAuthn can require fresh authentication; otherwise an existing session may be reused. The response assertion preserves the actual authentication time. When authnRequestConfig.requireSignedAuthnRequests is true, the request must be signed using the configured service provider signing certificate.
application/json
POST
/api/saml/{id}/authn
cURL (application/json)
curl \
--request POST 'https://[tenant_id].logto.app/api/saml/{id}/authn' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"SAMLRequest": "string",
"RelayState": "string"
}'
curl \
--request POST 'https://[tenant_id].logto.app/api/saml/{id}/authn' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/x-www-form-urlencoded" \
--data 'SAMLRequest=string&RelayState=string'
Request examples
{
"SAMLRequest": "string",
"RelayState": "string"
}