NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2555 most downloaded on PyPI
Python implementation of SAML Version 2 Standard
Last release 17 days ago
17 Sep 2026
Release timing varies
gaps range from 9 days to 13 months
Most releases are documented
notes for 47 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
66 releases · first in 2013
Resolve CVE-2026-26007 by migrating to the from pyOpenSSL to the cryptography APIs
Remove import of deprecated cgi module
shelve.open and dbm errorscgi moduledatetime.utcnow() by datetime.now(timezone.utc)importlib_metadata dependencyimportlib_resources dependencyOne column per quarter.
7.5.3 (2025-10-04) #973 Fix prepare_for_negotiated_authenticate to avoid double signing redirect requests
Include the XSD of the XML Encryption Syntax and Processing Version 1.1 to the schema validator
deps: restrict pyOpenSSL up to v24.2.1 until it is replaced
Fix missing requested attributes from the ACS
Use the set crypto_backend when creating the entity metadata
Fix subject-id requirements processing
Ensure the ID of each Signature element is unique when signing an encrypted assertion
Fix subject-id requirements processing
During metadata generation, render extensions both for EntityDescriptor and IdPSSODescriptor
>=3.5 and <5Accept and forward sign and digest alg information when creating a metadata string
Remove deprecated cryptography backend param
registration_info_typ method on saml2.mdstore.MetadataStore to get the registration information from an EntityDescriptor servicesStatusCode in an error responsesaml2.mdstore.MetadataStore; from sbibmd_scopes to shibmd_scopesxs:date AttributeValue typexs:string as the type of the AttributeValue text nodehttp_client_timeout to set a timeout on the HTTP calls by the httpbase modulefix assertion policy filter to try to resolve the local_name using the friendly name if it failed with the name_format
Process and verify the metadata signature for EntitiesDescriptor and EntityDescriptor
The following breaking changes are not reflected in the version by mistake:
The following breaking changes are not reflected in the version by mistake:
saml2.mdstore.Metadata::certs used to return a list of certificate data - List[str].
This method has now changed to return a list of tuples - List[Tuple[str, str]] - where the first item in the tuple holds the key name, and the second the certificate data.Changes:
Preserve order of response bindings on IdP-initiated logout
BREAKING Replace encryption method rsa-1_5 with rsa-oaep-mgf1p
Add shibmd_scopes metadata extractor
Fix the parser to take into account both the xs and xsd namespace prefixes
Fix processing of invalid SAML XML documents - [CVE-2021-21238]
Fix processing of invalid SAML XML documents - CVE-2021-21238
Fix unspecified xmlsec1 key-type preference - CVE-2021-21239
Add more tests regarding XSW attacks
Add XML Schemas for SAML2 and common extensions
Fix the XML parser to not break on ePTID AttributeValues
Fix the initialization value of the return_addrs property of the StatusResponse object
Fix SWAMID entity-category policy regarding eduPersonTargetedID
data: use importlib to load package data (backwards compatibility through the importlib_resources package)
docs: improve the documentation for the signing_algorithm and digest_algorithm options
examples: fix the logging configuration of the example-IdP
tests: allow tests to pass on 32bit systems by properly choosing dates in test XML documents
tests: improvements on the generation of response and assertion objects
tests: expand tests on python-3.9 and python-3.10-dev
Indicate minimum required python version during installation
Add preferred signing and digest algorithms configuration options: Use the new configuration options signing_algorithm and digest_algorithm.
signing_algorithm and digest_algorithm.Signature and SigAlg were not included.Fix extraction of RegistrationInfo when no information is available
Allow to specify policy configurations based on the registration authority.
Allow to specify policy configurations based on the registration authority.
Add new configuration option logout_responses_signed to sign logout responses.
When available and appropriate return the ResponseLocation along with the Location attribute.
Always use base64.encodebytes; base64.encodestring has been dropped.
Examples: fix IdP example that was outputing debug statements on stdout that became part of its metadata.
CI/CD: Use Ubuntu bionic as the host to run the CI/CD process.
CI/CD: Pre-releases are now available on test.pypi.org. Each commit/merge on the master branch autotically creates a new pre-release. To install a prelease, run:
$ pip install -U -i https://test.pypi.org/simple --extra-index-url https://pypi.org/simple pysaml2
Fix the generated xsd:ID format for EncryptedData and EncryptedKey elements
Fix signed logout requests flag
Differentiate between metadata NameIDFormat and AuthnRequest NameIDPolicy Format
name_id_format to set the <NameIDPolicy Format="..."> attribute now
need to use the new configuration option name_id_policy_format.Fix generation of signed metadata
additional_cert_files configuration optionFix check for nameid_format set to the string "None" in the configuration
Fix presence of empty eIDAS RequestedAttributes element on AuthnRequest
support eIDAS RequestedAttributes per AuthnRequest
Fix XML Signature Wrapping (XSW) vulnerabilities - CVE-2020-5390
Add mdstore methods to extract mdui uiinfo elements
name_id_format_allow_createFix deprecation warning regarding the cgi module - use the html module when available
Add support for MDQ signature verification
Fix for response status error case handling (introduced in v4.6.5)
Thanks @rectalogic @skanct
Make use of the sign argument to entity.Entity::apply_binding when binding is HTTP-Redirect. Reminder: use [authn_requests_signed configuration option
Thanks to @johanlundberg @skoranda @yuqing0708 @erakli
Do not map between attribute FriendlyName and attribute Name when no attributemaps are provided.
Do not map between attribute FriendlyName and attribute Name when no attributemaps are provided.
Refactor AttributeValueBase::set_text method.
Refactor AttributeValueBase::set_text method.
Allow multiple AttributeStatement tags per Assertion
Always generate a random IV for AES operations / Address CVE-2017-1000246
The SP by default now, requires the IdP to _sign authentication responses_. This is configurable through the [want_response_signed][0] option. To pres
Breaking release!
The SP by default now, requires the IdP to sign authentication responses. This is configurable through the want_response_signed option. To preserve the old behaviour, set want_response_signed to False.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
A couple of API changes necessitated an major version number change. The changes where concerned with non-xml signing and signature verification.
A couple of API changes necessitated an major version number change. The changes where concerned with non-xml signing and signature verification.
The API of the functions verify_redirect_signature (sigver.py) and http_redirect_message (pack.py) was changes. As where the method use_http_get of the class HTTPBase (httpbase.py)
Nothing published for this version
All parts of the package is now collected in one module. This is a change that breaking change compared to earlier releases hence the major version ch…
Three major changes:
A couple of security fixes plus maintenance updates.
A couple of security fixes plus maintenance updates.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →