PackageTrack
Sign in Get early access

onelogin/php-saml

PHP SAML Toolkit

4.3.2 50M downloads/mo #603 most downloaded on Packagist SAML-Toolkits/php-saml

What this package is like to depend on

Last release 3 months ago

11 May 2026

Release timing varies

gaps range from 2 weeks to 1.9 years

Some releases are documented

notes for 20 of 59 stable releases

Nothing withdrawn

no release was ever pulled

12 years old

59 releases · first in 2014

6 releases in the last 12 months

see the full history below

Release timeline

59 releases · Jun 2014 to May 2026
2015 2017 2019 2021 2023 2025
Release Pre-release

Releases

latest 59
  1. 4.3.2 07 May 2026
    Release notes
    Open source →
  2. 4.3.1 09 Dec 2025
    Release notes
    Open source →
  3. 4.3.0 25 May 2025
    Release notes
    • PHP 8.4 Compatibility via #600 and #607.
    • #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
    • #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
    • #594 Add support for encrypted name id in encrypted assertion
    • Fix buildWithBaseURLPath. See #581
    • Doc fix typo
    • Remove Travis CI references
    Open source →
  4. 4.2.0 30 May 2024
    Release notes
    • #586 IdPMetadataParser::parseRemoteXML - Add argument for setting whether to validate peer SSL certificate
    • #585 Declare conditional return types
    • #577 Allow empty NameID value when no strict or wantNameId is false
    • #570 Support X509 cert comments
    • #569 Add parameter to exclude validUntil on SP Metadata XML
    • #551 Fix compatibility with proxies that extends HTTP_X_FORWARDED_HOST
    • LogoutRequest and the LogoutResponse object to separate functions
    • Make Saml2\Auth can accept a param $spValidationOnly
    • Fix typos on readme.
    • #480 Fix typo on SPNameQualifier mismatch error message
    • Remove unbound version constraints on xmlseclibs
    • Update dependencies
    • Fix test payloads
    • Remove references to OneLogin.
    Open source →
  5. 4.1.0 15 Jul 2022

    Nothing published for this version

  6. 4.0.1 27 Jun 2022

    Nothing published for this version

  7. 4.0.0 02 Mar 2021

    Nothing published for this version

  8. 3.8.2 11 May 2026
    Release notes
    • Update xmlseclibs version requirement to 3.1.5 due CVE-2026-32313
    • Force Fix phpunit > 8.5.51 due GHSA-vvj3-c3rp-c85p. Adapt tests to work with that phpunit version
    • Drop support PHP < 7.2
    Open source →
  9. 3.8.1 09 Dec 2025
    Release notes

    Security:

    Open source →
  10. 3.8.0 25 May 2025
    Release notes
    • #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
    • #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
    • #594 Add support for encrypted name id in encrypted assertion
    • Fix buildWithBaseURLPath. See #581
    • Doc fix typo
    • Remove Travis CI references
    Open source →
  11. 3.7.0 30 May 2024

    Nothing published for this version

  12. 3.6.1 02 Mar 2021

    Nothing published for this version

  13. 3.6.0 19 Feb 2021

    Nothing published for this version

  14. 3.5.1 03 Dec 2020

    Nothing published for this version

  15. 3.5.0 26 Nov 2020

    Nothing published for this version

  16. 3.4.1 25 Nov 2019

    Nothing published for this version

  17. 3.4.0 19 Nov 2019

    Nothing published for this version

  18. 3.3.1 06 Nov 2019

    Nothing published for this version

  19. 3.3.0 11 Sep 2019

    Nothing published for this version

  20. 3.2.1 25 Jun 2019

    Nothing published for this version

  21. 3.2.0 24 Jun 2019

    Nothing published for this version

  22. 3.1.1 11 Mar 2019

    Nothing published for this version

  23. v3.1.0 28 Jan 2019

    Nothing published for this version

  24. v3.0.0 02 Oct 2018

    Nothing published for this version

  25. 2.21.2 10 Dec 2025
    Release notes

    The version 2.21.1 was released with the wrong version.json file and missed Changelog.
    The 2.21.2 version has the same code than 2.21.2 but set right version and update Changelog

    Open source →
  26. 2.21.1 09 Dec 2025
    Release notes

    Security:

    Open source →
  27. 2.21.0 25 May 2025
    Release notes
    • #619 Add Parameter checking on validateBinarySign, inspired on CVE-2025-27773
    • #603 Fix typo in ignoreValidUntil that breaks metadata. Add parameter to exclude validUntil on Settings getSPMetadata
    • #594 Add support for encrypted name id in encrypted assertion
    • Fix buildWithBaseURLPath. See #581
    • Doc fix typo
    • Remove Travis CI references
    Open source →
  28. 2.20.0 30 May 2024

    Nothing published for this version

  29. 2.19.1 02 Mar 2021

    Nothing published for this version

  30. 2.19.0 26 Nov 2020

    Nothing published for this version

  31. 2.18.1 25 Nov 2019

    Nothing published for this version

  32. 2.18.0 19 Nov 2019

    Nothing published for this version

  33. 2.17.1 06 Nov 2019

    Nothing published for this version

  34. 2.17.0 11 Sep 2019

    Nothing published for this version

  35. 2.16.0 24 Jun 2019

    Nothing published for this version

  36. v2.15.0 28 Jan 2019

    Nothing published for this version

  37. v2.14.0 17 Jun 2018

    Nothing published for this version

  38. v2.13.0 05 Mar 2018

    Nothing published for this version

  39. v2.12.0 06 Nov 2017

    Nothing published for this version

  40. 2.11.0 21 Jul 2017

    Nothing published for this version

  41. 2.10.7 19 May 2017

    Nothing published for this version

  42. 2.10.6 17 May 2017

    Nothing published for this version

  43. 2.10.5 13 Mar 2017

    Nothing published for this version

  44. 2.10.4 28 Feb 2017

    Nothing published for this version

  45. 2.10.3 11 Jan 2017

    Nothing published for this version

  46. 2.10.2 15 Nov 2016

    Nothing published for this version

  47. 2.10.1 26 Oct 2016

    Nothing published for this version

  48. 2.10.0 14 Oct 2016

    Nothing published for this version

  49. 2.9.1 19 Jul 2016

    Nothing published for this version

  50. 2.9.0 27 Jun 2016
    Release notes
    • Change the decrypt assertion process.
    • Add 2 extra validations to prevent Signature wrapping attacks.
    • Remove reference to wrong NameIDFormat: urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified should be urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    • 128 Test php7 and upgrade phpunit
    • Update Readme with more descriptive requestedAuthnContext description and Security Guidelines
    Open source →
  51. 2.8.0 12 May 2016
    Release notes
    • Make NameIDPolicy of AuthNRequest optional
    • Make nameID requirement on SAMLResponse optional
    • Fix empty URI support
    • Symmetric encryption key support
    • Add more Auth Context options to the constant class
    • Fix DSA_SHA1 constant on xmlseclibs
    • Set none requestedAuthnContext as default behaviour
    • Update xmlseclibs lib
    • Improve formatPrivateKey method
    • Fix bug when signing metadata, the SignatureMethod was not provided
    • Fix getter for lastRequestID parameter in OneLogin_Saml2_Auth class
    • Add $wantEncrypted parameter on addX509KeyDescriptors method that will allow to set KeyDescriptor[use='encryption'] if wantNameIdEncrypted or wantAssertionsEncrypted enabled
    • Add $stay parameter on redirectTo method. (login/logout supports $stay but I forgot add this on previous 2.7.0 version)
    • Improve code style
    Open source →
  52. 2.7.0 15 Feb 2016
    Release notes
    • Trim acs, slo and issuer urls.
    • Fix PHP 7 error (used continue outside a loop/switch).
    • Fix bug on organization element of the SP metadata builder.
    • Fix typos on documentation. Fix ALOWED Misspell.
    • Be able to extract RequestID. Add RequestID validation on demo1.
    • Add $stay parameter to login, logout and processSLO method.
    Open source →
  53. 2.6.1 09 Sep 2015
    Release notes
    • Fix bug on cacheDuration of the Metadata XML generated.
    • Make SPNameQualifier optional on the generateNameId method. Avoid the use of SPNameQualifier when generating the NameID on the LogoutRequest builder.
    • Allows the authn comparison attribute to be set via config.
    • Retrieve Session Timeout after processResponse with getSessionExpiration().
    • Improve readme readability.
    • Allow single log out to work for applications not leveraging php session_start. Added a callback parameter in order to close the session at processSLO.
    Open source →
  54. 2.6.0 17 Jul 2015
    Release notes
    • Set NAMEID_UNSPECIFIED as default NameIDFormat to prevent conflicts with IdPs that don't support NAMEID_PERSISTENT.
    • Now the SP is able to select the algorithm to be used on signatures (DSA_SHA1, RSA_SHA1, RSA_SHA256, RSA_SHA384, RSA_SHA512).
    • Change visibility of _decryptAssertion to protected.
    • Update xmlseclibs library.
    • Handle valid but uncommon dsig block with no URI in the reference.
    • login, logout and processSLO now return ->redirectTo instead of just call it.
    • Split the setting check methods. Now 1 method for IdP settings and other for SP settings.
    • Let the setting object to avoid the IdP setting check. required if we want to publish SP SAML Metadata when the IdP data is still not provided.
    Open source →
  55. 2.5.0 05 Jun 2015
    Release notes
    • Do accessible the ID of the object Logout Request (id attribute).
    • Add note about the fact that PHP 5.3 is unsupported.
    • Add fingerprint algorithm support.
    • Add dependences to composer.
    Open source →
  56. 2.4.0 03 Mar 2015
    Release notes
    • Fix wrong element order in generated metadata.
    • Added SLO with nameID and SessionIndex in demo1.
    • Improve isHTTPS method in order to support HTTP_X_FORWARDED_PORT.
    • Set optional the XMLvalidation (enable/disable it with wantXMLValidation security setting).
    Open source →
  57. 2.3.0 13 Jan 2015
    Release notes
    • Resolve namespace problem. Some IdPs uses saml2p:Response and saml2:Assertion instead of samlp:Response saml:Assertion.
    • Improve test and documentation.
    • Improve ADFS compatibility.
    • Remove unnecessary XSDs files.
    • Make available the reason for the saml message invalidation.
    • Adding ability to set idp cert once the Setting object initialized.
    • Fix status info issue.
    • Reject SAML Response if not signed and strict = false.
    • Support NameId and SessionIndex in LogoutRequest.
    • Add ForceAuh and IsPassive support.
    Open source →
  58. 2.1.0 03 Jul 2014
    Release notes
    • The isValid method of the Logout Request is now non-static. (affects processSLO method of Auth.php).
    • Logout Request constructor now accepts encoded logout requests.
    • Now after validate a message, if fails a method getError of the object will return the cause.
    • Fix typos.
    • Added extra parameters option to login and logout methods.
    • Improve Test (new test, use the new getError method for testing).
    • Bugfix namespace problem when getting Attributes.
    Open source →
  59. 2.0.0 04 Jun 2014
    Release notes
    • New PHP SAML Toolkit (SLO, Sign, Encryptation).
    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive