Local logout ends this application's session; SAML single logout exchanges signed protocol messages with the asserting party.
Spring Security SAML logout: local session versus single logout
Decide which session ends
A dispatcher clicks Sign out. A local logout clears this service provider's authenticated session but can leave the identity-provider session active, allowing another login without a password prompt. SAML single logout can involve the asserting party and other service providers when the IdP supports it. Spring Security supports both relying-party and asserting-party initiated flows. Session ownership still determines what the application invalidates locally.
Configure the protocol as a pair
Single logout requires the asserting party to support it, compatible endpoints, and signing credentials on the relying party. The default SAML logout processing endpoint is /logout/saml2/slo. A changed endpoint must be reflected in both registration and IdP configuration. Keep a separate local-only endpoint if the product intentionally offers it; label its effect accurately.
Test both directions
Run an RP-initiated logout and inspect the signed request and response. Then initiate logout at the IdP and assert the local session stops authorizing requests. Also simulate an unavailable IdP: define whether the local session is cleared, whether retry is possible, and what the user sees.
Implementation sketch
http.logout(local -> local.logoutUrl("/logout"))
.saml2Logout(saml -> saml.logoutUrl("/saml2/logout"));Cost and verification
Single logout adds signed XML exchanges, network latency and certificate maintenance. Local logout is cheaper but cannot promise termination of the IdP session.
Common Mistakes
- Do not label local logout as logout from every federated application.
- Do not enable single logout without IdP support and signing credentials.
- Do not change the SAML logout endpoint only on the application side.
Read next
Spring Security SAML relying party: align registration, ACS and metadata, Spring SAML session revocation: closing the browser is not deprovisioning, Spring Security OAuth2 login: callback, identity and browser session.
