Openid Sso

Advanced OpenID, OIDC, SAML, and SSO security testing methodology for bug bounty and application security work. Use when testing or reviewing SSO login, SAML assertions, OpenID Connect ID tokens, SSO domain enforcement, JIT/SCIM provisioning, RelayState, signed assertions, JWT client-side generation, organization joins, enterprise identity matching, SSO token theft, SSO DoS, and workflows where federated identity grants account, tenant, or internal-service access.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/openid-sso commit 857a0f64c1

Frequently asked questions

npx skillmds@latest add yafet-dev/openid-sso