Non-goals

What SAMLscope deliberately does not do

Certification or authentication

SAMLscope has no legitimacy as a certification body. It stops at “Tested.”

SAML 1.x

Out of scope entirely.

Vendor-dedicated code

Every implementation is equally an external implementation, including the maintainers' own.

A production IdP or SP

A Test Peer is the other party for testing. It is not intended for production use.

Performance or load testing

Out of scope.

Intrusive operations

Even the future Security Profile phase stays on the normal protocol path with the target.

Frozen terminology

These rules are permanent, stated in the README and on every publication page footer.

Permitted
  • Tested against SAML V2.0 Implementation Profile for Federation Interoperability v1.1
  • Conformance Test Result
  • Test Report
Prohibited
  • Certified / Certification
  • Compliant / Compliance, as a title
  • Approved / Endorsed / Validated by <organization>
  • Kantara or OASIS named as if they were certifying bodies

License

Apache License 2.0. Contributions use the Developer Certificate of Origin; no CLA is required.