$npx skillfedfor your agent

python3-saml

Saml Python Toolkit. Add SAML support to your Python software using this library

With conditionsPyPI SecurityReleased Oct 20239.4M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — python3_saml-1.16.0-py2-none-any.whl · python3_saml-1.16.0-py3-none-any.whl
v1.16.0 · released 2023-10-09

Yes, with conditions. The library is mature, permissively licensed, and has no known vulnerabilities. Install friction is low and it covers the full SAML 2.0 SP workflow. However, maintenance is aging (last release 2023-10-09); verify that it supports your IdP's current SAML profile and that you can manage the xmlsec and lxml system dependencies in your deployment environment. Suitable for production use if you can commit to security best practices, especially enabling strict mode.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires xmlsec and lxml system libraries; lxml should be installed from source (not binary) to avoid libxml2 version conflicts with xmlsec.
  • Low install friction with no runtime dependencies.
  • Maintenance is aging—last release was 2023-10-09 and last commit 2026-01-14—but the repository remains active and unarchived with a stable user base.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, making it suitable for most deployment contexts.

last release 2023-10-09 (1040 days) · last repo commit 2026-01-14 · 755 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 9,429,292 downloads/mo, #1,534 on PyPI

Verify before relying

pip install python3-saml

Import the toolkit and instantiate with request and settings to handle SSO and SLO flows.
  • Whether xmlsec and lxml system dependencies are pre-installed or require separate setup in typical deployment environments
  • Current status of the library's compatibility with modern IdP implementations and SAML 2.0 profile updates
  • Specific API usage patterns and method signatures for SSO/SLO workflows
Same gist for agents: .md · .json

What it is and what it does

python3-saml is a SAML 2.0 toolkit that converts your Python application into a Service Provider capable of federating with identity providers. It handles the full SSO and SLO lifecycle—both SP-initiated and IdP-initiated flows—and manages assertion encryption, signature validation, and metadata publication. The library is session-less, delegating session management to your application layer, and provides both high-level and low-level APIs for flexibility.

The toolkit requires Python 3.7 or later and depends on xmlsec and lxml for XML cryptography and parsing. It implements the SAML 2.0 Web Browser SSO Profile and has been in production use since 2015. The library emphasizes security best practices, including strict mode validation by default and defenses against XML external entity attacks, signature wrapping, and replay attacks.

Use it for

  • Integrate enterprise SSO into a SaaS application to allow users to authenticate via corporate identity providers
  • Build a federated B2B platform where partner organizations can authenticate their users without sharing credentials
  • Implement single logout across multiple applications by handling IdP-initiated SLO requests
  • Publish SP metadata for discovery and automated configuration by identity provider administrators
  • Validate digitally signed SAML assertions and encrypted nameIds from trusted identity providers

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

The library is mature, permissively licensed, and has no known vulnerabilities. Install friction is low and it covers the full SAML 2.0 SP workflow. However, maintenance is aging (last release 2023-10-09); verify that it supports your IdP's current SAML profile and that you can manage the xmlsec and lxml system dependencies in your deployment environment. Suitable for production use if you can commit to security best practices, especially enabling strict mode.

Install

python3-saml on PyPI

Before you install

Low install friction with no runtime dependencies. Maintenance is aging—last release was 2023-10-09 and last commit 2026-01-14—but the repository remains active and unarchived with a stable user base.

Requires xmlsec and lxml system libraries; lxml should be installed from source (not binary) to avoid libxml2 version conflicts with xmlsec.

License in practice

MIT license permits commercial and private use with minimal restrictions, making it suitable for most deployment contexts.

Quickstart

pip install python3-saml

Import the toolkit and instantiate with request and settings to handle SSO and SLO flows.

Verify before relying

  • Whether xmlsec and lxml system dependencies are pre-installed or require separate setup in typical deployment environments
  • Current status of the library's compatibility with modern IdP implementations and SAML 2.0 profile updates
  • Specific API usage patterns and method signatures for SSO/SLO workflows

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAging 1,040 days since the last release
Last repo commit
First released
Downloads9,429,292 / month, #1,534 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: System AdministratorsOperating System :: OS IndependentProgramming Language :: Python :: 2.7Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: python3_saml-1.16.0-py2-none-any.whl; python3_saml-1.16.0-py3-none-any.whl

Tags

Capabilities
saml service providersingle sign-on ssosaml authenticationidentity provider federationsaml2 pythonxml security authenticationenterprise sso
Topics
saml-federationsso-authenticationxml-security
PyPI keywords
samlsaml2ssoxmlsecfederationidentity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “identity provider federation”

  • python3-samlTurns a Python application into a SAML 2.0 Service Provider, enabling…
  • djangosaml2idp2Implements the SAML 2.0 Identity Provider side for Django…
  • pysaml2PySAML2 is a pure Python implementation of SAML Version 2 Standard…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also pysaml2 · python-cas · djangosaml2 · djangosaml2idp2 · descope · grafana-django-saml2-auth · signxml · onelogin · python-openid · xmlsec