Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 33 Next »

Security Assertion Markup Language (SAML) is an XML-based format for exchanging authentication and authorization data between an identity provider and a service provider.

Checkmarx’s Static Application Security Test (CxSAST) has just become SAML 2.0 aware and can now be configured to act as a SAML 2.0 Service Provider. SAML supports the user lifecycle by retrieving users from the Corporate Identity Provider (IdP) and defining them in CxSAST. This allows for more centralized and enhanced user management.  

  1. The user makes a request to the Service Provider (e.g. CxSAST) for a specific resource
  2. The Service Provider detects that authentication is required and redirects the Web Browser to the Identity Provider (e.g. OKTA)
  3. The Web Browser accesses the Identity Provider and the user is checked for authentication
  4. Once the user receives authentication, the Identity Provider sends a response back to the Web Browser
  5. The Web Browser then sends an authentication token to the Service Provider
  6. The Service Provider processes the assertion and the user is automatically logged in.




  • No labels