Integrate Login.gov as a SAML 2.0 identity provider for a government service, as an alternative to Login.gov's OpenID Connect integration

domain: developers.login.gov · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Note that Login.gov itself recommends OpenID Connect over SAML for new integrations, so confirm SAML is required by your service's existing stack before proceeding.
  2. Configure your service provider with Login.gov's SingleSignOnService and SingleLogoutService endpoints, using the year-suffixed URLs (e.g. /api/saml/auth2026, /api/saml/logout2026) and the persistent v4-UUID NameID format.
  3. Retrieve Login.gov's IdP metadata, or its signing certificate directly, so your app can validate the signature on SAML responses; pulling from the metadata endpoint is preferred since it avoids manual certificate re-uploads.
  4. Use a maintained SAML library for your language rather than hand-rolling XML signature validation, per Login.gov's own guidance that the standard is complex to implement correctly.
  5. Test the full authentication and logout flow against the identity sandbox environment using Login.gov's open-source example client before requesting Partner Portal production credentials.
  6. Track Login.gov's annual certificate rotation: new year-suffixed endpoints and signing certificates are issued each spring with about a month of overlap, and old endpoints are retired, so plan a migration window rather than hardcoding a single year's URLs.

Known gotchas

Related routes

Integrate Login.gov OIDC for a government service application
secure.login.gov · 6 steps · unrated
Integrate a SAML 2.0 service provider with an identity provider
docs.oasis-open.org · 6 steps · unrated
Configure Login.gov OIDC with private_key_jwt client authentication and IAL/AAL acr_values
developers.login.gov · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans