One-click SAML metadata inspection for Chrome.
Simplify SAML turns SAML 2.0 metadata into the values you actually need to configure an integration.
Open a SAML metadata page, click the extension, and get a clean one-screen summary — no uploading metadata, no account, no analytics, and no digging through XML.
Chrome Web Store · Project page · Privacy policy
Depending on the metadata, Simplify SAML can surface:
- Entity ID
- Primary ACS, SSO, and SLO endpoints
- Alternate endpoints, kept collapsed until needed
- NameID formats
- Requested attributes, including required attributes
AuthnRequestsSigned,WantAssertionsSigned, andWantAuthnRequestsSigned- Signing and encryption certificates
- Certificate validity dates
- One-click Copy PEM and Download PEM
- Multiple entities from federation metadata
- Nested
EntitiesDescriptormetadata - Application / organization names when published
- Conservative IdP/vendor recognition
The goal is intentionally simple:
Click → copy the integration values → close.
Simplify SAML keeps complicated metadata simple.
When metadata contains multiple endpoints, Simplify SAML quietly chooses the most useful primary value and keeps the rest behind an alternate disclosure.
For example:
- Default ACS wins when explicitly marked
- HTTP-POST is preferred for ACS
- HTTP-Redirect / HTTP-POST are preferred for SSO and SLO
- HTTPS is preferred when otherwise equivalent
Simplify SAML supports:
- Multiple
EntityDescriptorentries - Nested
EntitiesDescriptorgroups - Inherited
validUntilandcacheDuration - Multiple signing certificates / rollover metadata
AttributeConsumingServiceRequestedAttribute
Complexity stays in the parser — not in the interface.
Simplify SAML is designed for identity and security workflows where metadata may contain internal URLs, entity identifiers, certificates, and other configuration details.
- Metadata is processed locally in Chrome
- Nothing is uploaded to a Simplify SAML server
- No analytics
- No advertising
- No tracking or telemetry
- No user accounts
- No persistent access to every website
- Analysis results use temporary
chrome.storage.session
Page access happens only when you explicitly click the extension.
Read the full Privacy Policy.
Simplify SAML uses a small Manifest V3 permission set:
Temporarily allows access to the current tab after you explicitly click the extension.
Injects the packaged Simplify SAML content script into that active tab so the displayed metadata can be read.
Uses chrome.storage.session to temporarily pass the parsed result and raw XML to the summary page.
Simplify SAML does not require <all_urls>.
Install Simplify SAML from the Chrome Web Store →
-
Clone this repository:
git clone https://github.com/iamalexhoang/simplify-saml.git
-
Open
chrome://extensions -
Enable Developer mode
-
Click Load unpacked
-
Select the repository folder
-
Pin Simplify SAML to the toolbar if desired
The extension is intentionally small:
background.js— handles the user click, temporary session result, and summary-tab flowcontent.js— reads the XML displayed in the active tabparser.js— parses SAML metadata into structured dataanalyzer.js— generates limited actionable observationssummary.html/summary.js/summary.css— renders the one-screen integration summary
All parsing happens locally.
Simplify SAML is focused on SAML 2.0 metadata containing:
EntityDescriptorEntitiesDescriptorSPSSODescriptorIDPSSODescriptor
If the extension detects a SAML Response, AuthnRequest, Logout message, or other non-metadata SAML XML, it identifies the document type instead of pretending it is metadata.
The current release keeps the one-screen workflow while adding restrained color and clearer visual hierarchy.
Recent releases also added:
- Metadata Compatibility
- Nested federation support
- Requested attributes
- Smart primary endpoint selection
- Collapsed alternates
- Session-only storage
- Minimal
activeTabpermissions - Signing/encryption certificate context
- New Simplify SAML icon
Issues and pull requests are welcome. Please keep the product philosophy in mind:
If a feature does not make click → integrate faster or safer, it probably does not belong on the main screen.
See CONTRIBUTING.md for additional guidance.
For security-related information, see SECURITY.md.
Please avoid posting real internal SAML metadata, private URLs, or sensitive identity configuration in public issues.
MIT License. See LICENSE.md.