IdP/OP Playground

This page lists options for testing whether an IdP works properly over SAML and OIDC.

SAML

Test authentication and authn parameters

This section was deleted, because samltest.id no longer works.

You can use https://aai-playground.ics.muni.cz/ to test authentication but you’ll have to test authn parameters manually.

REFEDS MFA profile

To only test REFEDS MFA profile, go to mfa.eduid.cz

Attribute release (only for IdPs in the federation)

To test attribute release in eduID.cz, go to https://attributes.eduid.cz/

To test attribute release in eduGAIN and profiles such as R&S and CoCo, go to https://release-check.edugain.org/

Other tools for SAML testing

OIDC

Test authentication

  1. Go to https://oidcdebugger.com/ via one of the quick links below

  2. Check Use PKCE

  3. Click SEND REQUEST

ProxyIdP instance

Authenticate

Logout

ProxyIdP instance

Authenticate

Logout

 

MU

MU logout

e-INFRA CZ

e-INFRA CZ logout

CESNET e-infrastructure

CESNET e-infrastructure logout

LS AAI code w/PKCE

ELIXIR code w/PKCE (via LS AAI)

BBMRI code w/PKCE (via LS AAI)

LS AAI logout

ELIXIR logout

BBMRI logout

Test authn parameters, REFEDS MFA profile

To test additional parameters:

  1. Follow a quick link from the table above

  2. Check Use PKCE

  3. Copy the generated URL

  4. Add a query parameter to the URL:

    1. &prompt=login to test forced authentication

    2. &prompt=none to test passive authentication

    3. &acr_values=https%3A%2F%2Frefeds.org%2Fprofile%2Fmfa to test REFEDS MFA profile

    4. &prompt=login&acr_values=https%3A%2F%2Frefeds.org%2Fprofile%2Fmfa to force full MFA

    5. &acr_values=https%3A%2F%2Frefeds.org%2Fprofile%2Fsfa to test REFEDS SFA profile

Support: perun@cesnet.cz