onelogin/php-saml
PHP SAML Toolkit
4.3.2
50M downloads/mo
#603 most downloaded on Packagist
SAML-Toolkits/php-saml
What this package is like to depend on
Last release 3 months ago
11 May 2026
Release timing varies
gaps range from 2 weeks to 1.9 years
Some releases are documented
notes for 20 of 59 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
59 releases · first in 2014
6 releases in the last 12 months
see the full history below
Release timeline
59 releases · Jun 2014 to May 2026Releases
latest 59-
4.3.207 May 2026 -
4.3.109 Dec 2025 -
4.3.025 May 2025Release notes
Open source →- PHP 8.4 Compatibility via #600 and #607.
- #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
- #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
- #594 Add support for encrypted name id in encrypted assertion
- Fix buildWithBaseURLPath. See #581
- Doc fix typo
- Remove Travis CI references
-
4.2.030 May 2024Release notes
Open source →- #586 IdPMetadataParser::parseRemoteXML - Add argument for setting whether to validate peer SSL certificate
- #585 Declare conditional return types
- #577 Allow empty NameID value when no strict or wantNameId is false
- #570 Support X509 cert comments
- #569 Add parameter to exclude validUntil on SP Metadata XML
- #551 Fix compatibility with proxies that extends HTTP_X_FORWARDED_HOST
- LogoutRequest and the LogoutResponse object to separate functions
- Make Saml2\Auth can accept a param $spValidationOnly
- Fix typos on readme.
- #480 Fix typo on SPNameQualifier mismatch error message
- Remove unbound version constraints on xmlseclibs
- Update dependencies
- Fix test payloads
- Remove references to OneLogin.
-
4.1.015 Jul 2022Nothing published for this version
-
4.0.127 Jun 2022Nothing published for this version
-
4.0.002 Mar 2021Nothing published for this version
-
3.8.211 May 2026Release notes
Open source →- Update xmlseclibs version requirement to 3.1.5 due CVE-2026-32313
- Force Fix phpunit > 8.5.51 due GHSA-vvj3-c3rp-c85p. Adapt tests to work with that phpunit version
- Drop support PHP < 7.2
-
3.8.109 Dec 2025Release notes
Open source →Security:
- Update xmlseclibs version requirement to 3.1.4 due CVE-2025-66475
-
3.8.025 May 2025Release notes
Open source →- #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
- #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
- #594 Add support for encrypted name id in encrypted assertion
- Fix buildWithBaseURLPath. See #581
- Doc fix typo
- Remove Travis CI references
-
3.7.030 May 2024Nothing published for this version
-
3.6.102 Mar 2021Nothing published for this version
-
3.6.019 Feb 2021Nothing published for this version
-
3.5.103 Dec 2020Nothing published for this version
-
3.5.026 Nov 2020Nothing published for this version
-
3.4.125 Nov 2019Nothing published for this version
-
3.4.019 Nov 2019Nothing published for this version
-
3.3.106 Nov 2019Nothing published for this version
-
3.3.011 Sep 2019Nothing published for this version
-
3.2.125 Jun 2019Nothing published for this version
-
3.2.024 Jun 2019Nothing published for this version
-
3.1.111 Mar 2019Nothing published for this version
-
v3.1.028 Jan 2019Nothing published for this version
-
v3.0.002 Oct 2018Nothing published for this version
-
2.21.210 Dec 2025Release notes
Open source →The version 2.21.1 was released with the wrong version.json file and missed Changelog.
The 2.21.2 version has the same code than 2.21.2 but set right version and update Changelog -
2.21.109 Dec 2025 -
2.21.025 May 2025Release notes
Open source →- #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
- #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
- #594 Add support for encrypted name id in encrypted assertion
- Fix buildWithBaseURLPath. See #581
- Doc fix typo
- Remove Travis CI references
-
2.20.030 May 2024Nothing published for this version
-
2.19.102 Mar 2021Nothing published for this version
-
2.19.026 Nov 2020Nothing published for this version
-
2.18.125 Nov 2019Nothing published for this version
-
2.18.019 Nov 2019Nothing published for this version
-
2.17.106 Nov 2019Nothing published for this version
-
2.17.011 Sep 2019Nothing published for this version
-
2.16.024 Jun 2019Nothing published for this version
-
v2.15.028 Jan 2019Nothing published for this version
-
v2.14.017 Jun 2018Nothing published for this version
-
v2.13.005 Mar 2018Nothing published for this version
-
v2.12.006 Nov 2017Nothing published for this version
-
2.11.021 Jul 2017Nothing published for this version
-
2.10.719 May 2017Nothing published for this version
-
2.10.617 May 2017Nothing published for this version
-
2.10.513 Mar 2017Nothing published for this version
-
2.10.428 Feb 2017Nothing published for this version
-
2.10.311 Jan 2017Nothing published for this version
-
2.10.215 Nov 2016Nothing published for this version
-
2.10.126 Oct 2016Nothing published for this version
-
2.10.014 Oct 2016Nothing published for this version
-
2.9.119 Jul 2016Nothing published for this version
-
2.9.027 Jun 2016Release notes
Open source →- Change the decrypt assertion process.
- Add 2 extra validations to prevent Signature wrapping attacks.
- Remove reference to wrong NameIDFormat: urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified should be urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
- 128 Test php7 and upgrade phpunit
- Update Readme with more descriptive requestedAuthnContext description and Security Guidelines
-
2.8.012 May 2016Release notes
Open source →- Make NameIDPolicy of AuthNRequest optional
- Make nameID requirement on SAMLResponse optional
- Fix empty URI support
- Symmetric encryption key support
- Add more Auth Context options to the constant class
- Fix DSA_SHA1 constant on xmlseclibs
- Set none requestedAuthnContext as default behaviour
- Update xmlseclibs lib
- Improve formatPrivateKey method
- Fix bug when signing metadata, the SignatureMethod was not provided
- Fix getter for lastRequestID parameter in OneLogin_Saml2_Auth class
- Add $wantEncrypted parameter on addX509KeyDescriptors method that will allow to set KeyDescriptor[use='encryption'] if wantNameIdEncrypted or wantAssertionsEncrypted enabled
- Add $stay parameter on redirectTo method. (login/logout supports $stay but I forgot add this on previous 2.7.0 version)
- Improve code style
-
2.7.015 Feb 2016Release notes
Open source →- Trim acs, slo and issuer urls.
- Fix PHP 7 error (used continue outside a loop/switch).
- Fix bug on organization element of the SP metadata builder.
- Fix typos on documentation. Fix ALOWED Misspell.
- Be able to extract RequestID. Add RequestID validation on demo1.
- Add $stay parameter to login, logout and processSLO method.
-
2.6.109 Sep 2015Release notes
Open source →- Fix bug on cacheDuration of the Metadata XML generated.
- Make SPNameQualifier optional on the generateNameId method. Avoid the use of SPNameQualifier when generating the NameID on the LogoutRequest builder.
- Allows the authn comparison attribute to be set via config.
- Retrieve Session Timeout after processResponse with getSessionExpiration().
- Improve readme readability.
- Allow single log out to work for applications not leveraging php session_start. Added a callback parameter in order to close the session at processSLO.
-
2.6.017 Jul 2015Release notes
Open source →- Set NAMEID_UNSPECIFIED as default NameIDFormat to prevent conflicts with IdPs that don't support NAMEID_PERSISTENT.
- Now the SP is able to select the algorithm to be used on signatures (DSA_SHA1, RSA_SHA1, RSA_SHA256, RSA_SHA384, RSA_SHA512).
- Change visibility of _decryptAssertion to protected.
- Update xmlseclibs library.
- Handle valid but uncommon dsig block with no URI in the reference.
- login, logout and processSLO now return ->redirectTo instead of just call it.
- Split the setting check methods. Now 1 method for IdP settings and other for SP settings.
- Let the setting object to avoid the IdP setting check. required if we want to publish SP SAML Metadata when the IdP data is still not provided.
-
2.5.005 Jun 2015Release notes
Open source →- Do accessible the ID of the object Logout Request (id attribute).
- Add note about the fact that PHP 5.3 is unsupported.
- Add fingerprint algorithm support.
- Add dependences to composer.
-
2.4.003 Mar 2015Release notes
Open source →- Fix wrong element order in generated metadata.
- Added SLO with nameID and SessionIndex in demo1.
- Improve isHTTPS method in order to support HTTP_X_FORWARDED_PORT.
- Set optional the XMLvalidation (enable/disable it with wantXMLValidation security setting).
-
2.3.013 Jan 2015Release notes
Open source →- Resolve namespace problem. Some IdPs uses saml2p:Response and saml2:Assertion instead of samlp:Response saml:Assertion.
- Improve test and documentation.
- Improve ADFS compatibility.
- Remove unnecessary XSDs files.
- Make available the reason for the saml message invalidation.
- Adding ability to set idp cert once the Setting object initialized.
- Fix status info issue.
- Reject SAML Response if not signed and strict = false.
- Support NameId and SessionIndex in LogoutRequest.
- Add ForceAuh and IsPassive support.
-
2.1.003 Jul 2014Release notes
Open source →- The isValid method of the Logout Request is now non-static. (affects processSLO method of Auth.php).
- Logout Request constructor now accepts encoded logout requests.
- Now after validate a message, if fails a method getError of the object will return the cause.
- Fix typos.
- Added extra parameters option to login and logout methods.
- Improve Test (new test, use the new getError method for testing).
- Bugfix namespace problem when getting Attributes.
-
2.0.004 Jun 2014