Introducing the next era of Duende IdentityServer.
Native SAML 2.0 in both directions. Provide SAML SSO to downstream partners and accept SAML assertions from upstream enterprise IdPs, all from the IdentityServer your team already controls.

Replace your third-party SAML extension or custom SAML code with a first-party, add-on module that covers both Identity Provider (IdP) and Service Provider (SP) roles. Issue assertions to downstream apps like Salesforce and Workday; accept them from upstream IdPs like Active Directory Federation Services (ADFS), Okta, and Ping. Bridges SAML and OIDC in either direction. Self-hosted, air-gap compatible, version-matched. One vendor, one roadmap, one support contract.
Issue SAML assertions to downstream service providers like Salesforce, Workday, internal portals, legacy apps. SP-Initiated and IdP-Initiated SSO, Single Logout (SLO), and a SAML metadata endpoint.
Accept SAML assertions from upstream enterprise IdPs like ADFS, Ping, Okta SAML to onboard partner and customer organizations. Request signature validation and inbound federation. All native to Duende IdentityServer v8.
Authenticate users upstream via OIDC and issue SAML assertions to downstream apps. Or accept SAML upstream and translate to OIDC for modern clients. One programming model, no parallel identity systems.
The SAML add-on matches your deployment and integrates natively with Duende IdentityServer v8.
Both capabilities are included as a single add-on - bidirectional SAML in one license.



First-party SAML 2.0 IdP and SP capabilities are available as a capability of Duende IdentityServer across eligible tiers:
Tier | Availability |
|---|---|
| Community Edition | Not available |
| Lite | Not available |
| Standard | Add-on, $4,000 flat fee |
| Advanced | Included |
| Custom | Included |
See the IdentityServer pricing page for full tier details.