A SAML relying-party registration binds service-provider settings to an asserting party and its trust material.
Spring Security SAML relying party: align registration, ACS and metadata
Treat metadata as a protocol contract
A corporate identity provider posts a response to the service provider's assertion consumer service, or ACS. Spring Security resolves a RelyingPartyRegistration to validate that exchange. Its default login processing path includes /login/saml2/sso/{registrationId}; metadata can be published per registration. The IdP and app must agree on the issuer, ACS and credentials. Forwarded host handling matters when a proxy changes the public origin.
Keep tenants separate
If two employers use different IdPs, give each a distinct registration and bind the login entry point to the tenant's trusted registration. Never let a user-supplied issuer string select an arbitrary registration. Store trust material through a reviewed rotation path and verify metadata changes before activation.
Run a real protocol test
Import the service-provider metadata into a test IdP, complete one login, then change the ACS or issuer and assert failure. Repeat behind the production proxy so generated URLs use the public origin.
Implementation sketch
http.authorizeHttpRequests(requests -> requests
.requestMatchers("/saml2/metadata/**").permitAll()
.anyRequest().authenticated())
.saml2Login(Customizer.withDefaults())
.saml2Metadata(Customizer.withDefaults());Cost and verification
Each login exchanges signed XML and creates a local authenticated session. Multi-IdP setups add registration and certificate rotation work; cache only metadata according to a defined freshness policy.
Common Mistakes
- Do not change the login processing path without updating the ACS in metadata and the IdP.
- Do not trust an IdP solely because its issuer string looks familiar.
- Do not expose an internal proxy host in published service-provider metadata.
Read next
Spring Security SAML validation: signatures, audience and clock window, Spring Security SAML attributes: map identity to local authority, Spring behind a proxy: trust forwarded headers only after the edge strips them.
Related boundary
Spring Security SAML logout: local session versus single logout
