SAML, an XML-based authentication protocol created in 2002 by committee, became the foundation of the single sign-on industry but is now considered overly complex and insecure due to flawed XML signature validation. The article traces SAML's origins in academia and corporate IT, its widespread adoption by companies like Okta and Ping Identity, and argues for its deprecation in favor of modern alternatives like OpenID Connect.
SAML, created in 2002 by OASIS as an XML-based authentication protocol, became foundational to the single sign-on industry but is now criticized for excessive complexity built on unreliable XML signature validation. The article argues SAML should be deprecated in favor of modern alternatives like OpenID Connect, tracing its origins in academic institutions and corporate IT adoption through the 2000s and beyond.