SP metadata
Read-onlyFetched by IdPs, federations and monitoring.
What the SP does per request: session check, redirect to the IdP, ACS handling, metadata and logout.
Category SAMLStack Shibboleth SP, mod_auth_mellon, SimpleSAMLphp SP, Spring Security SAMLJobs 25
Load tests a SAML service provider such as Shibboleth SP, mod_auth_mellon, SimpleSAMLphp SP or Spring Security SAML: SP metadata, a public page, a protected page without a session (the redirect to the IdP), the login handler, session status, assertion consumer calls with garbage or empty data, logout and an unauthenticated ramp.
It holds 25 ready-made jobs: 9 single scenarios and an enterprise test plan of 16 stages to run in order, 13 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.
Scenarios include SP metadata, public page behind the SP, protected page without a session, SP login handler and session status.
url to point at your own SAML service provider system, ideally a staging copy.urlprotectedPathpublicPathmetadataPathacsPathsessionPathloginPathlogoutPathFetched by IdPs, federations and monitoring.
Baseline: the SP module is in the request path but does not require a session.
The SP builds an AuthnRequest and redirects to the IdP. This is every new visitor's first request. Redirects are not followed.
Starts SP-initiated login explicitly.
Polled by SPAs to see whether the user is logged in.
Anyone can POST to the ACS URL. The SP must reject an invalid response cheaply (no signature check should run) and without crashing. A 4xx or the SP's error page counts as rejected.
Bots do this constantly.
Logout of a session that does not exist.
Ramps requests to a protected page to find where the SP and its session store slow down. Each request creates a session or a redirect record.
Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.
Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: protected page without a session.
Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: protected page without a session.
Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: protected page without a session.
Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: protected page without a session.
Step 5 of 10. Ramps to four times average over 10 minutes, then holds for 2. Finds where it degrades and HOW: gracefully (latency rises, errors stay low) or badly (errors, timeouts, crashes, restarts). Observation only, no gate. Reference request: protected page without a session.
Step 6 of 10. Reaches ten times average within 10 seconds and holds for 2 minutes: a campaign email, a news link, a failover. Checks autoscaling, queue limits and load shedding. Gate: at most 5% errors, because shedding load is acceptable and crashing is not. Reference request: protected page without a session.
Step 7 of 10. Run IMMEDIATELY after the spike, at average load for 5 minutes. Latency and errors must return to the baseline from step 2. If they do not, something is stuck: queues, connection pools, GC, an autoscaler cool-down. Gate: same as average load. Reference request: protected page without a session.
Step 8 of 10. One hour of steady load. Finds leaks and slow decay in memory, connections, file descriptors, disk, log volume and cache churn. Watch the resource graphs: any line that climbs and never flattens is a finding. Gate: at most 0.5% errors. Reference request: protected page without a session.
Step 9 of 10. Ramps to twenty times average over 20 minutes. Stop it when errors pass about 5%: the rate at that moment is your ceiling, and ceiling divided by peak is your capacity margin. Use a production-like environment, never production. Reference request: protected page without a session.
Step 10 of 10. Average load for 15 minutes. About 5 minutes in, cause the event you are testing: kill a pod or node, fail over the database, roll out a new version, drain a zone. Errors in the window are your real availability loss. Gate: at most 1% errors overall; read the time series for how long the dip lasted. Reference request: protected page without a session.
Sends Connection: close, so every request pays for a new TCP and TLS handshake: the cost for clients that do not reuse connections (scripts, some mobile SDKs, health checkers). Shows load balancer and TLS termination limits. Reference request: protected page without a session.
Same request identified as a search crawler. Tests WAF and bot-management rules and whether crawlers get cached or origin responses. Crawlers can easily be a third of all traffic. Reference request: protected page without a session.
Adds a 4 KB Cookie header, like a logged-in user with many tracking cookies. Proxies and servers reject headers around 8 KB, so this shows how close you are to that limit. Reference request: protected page without a session.
A fleet of synthetic monitors checking the URL with HEAD requests every 30 seconds from 20 locations, plus load balancer probes. Cheap each, constant in total. Reference request: protected page without a session.
All sessions were created in the morning, so they expire together and every user is redirected to the IdP at the same moment. Ramps unauthenticated hits to ten times normal. Reference request: protected page without a session.
The ACS URL accepts POSTs from anyone. Ten times normal garbage submissions for 2 minutes: the SP must reject them cheaply and keep serving real users. Reference request: ACS with a garbage SAMLResponse.
The SAML service provider template has 25 jobs: 9 single scenarios and an enterprise test plan of 16 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include SP metadata, public page behind the SP, protected page without a session and SP login handler. 13 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.
Open the template in BLASTA and set url, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new saml-sp with your address.
All 25 jobs in this template are read-only: they request pages or data and do not change anything. Even so, a load test can slow a live system down, so start with a low rate and prefer a staging copy. Only test systems you own or have permission to test.
Welcome back. Sign in to run and review load tests.
Send the confirmation email again
Just looking? Try a quick test without an account
Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.
Queries are read-only unless Allow writes is on.
Multi-statement input and writable CTEs (WITH d AS (DELETE…)) are always refused.
For MQTT, LDAP, AMQP and other binary protocols. The templates fill this in for you.
The address accepts host:port or tcp://host:port.
Leave this empty to only test the connection handshake.
No results yet
Set up a target above and press Start test. Charts and numbers appear here as the test runs.
Ready-made jobs for common systems. Search by system, protocol or what you want to test (wordpress, saml, redis, spike, login storm…), pick a job, and it opens on the Test page ready to run.
You are browsing as a visitor: you can read every template and job. Sign in or create an account to use them.
No templates match
Try a shorter search, or a system name such as keycloak, postgres or soap.
You are browsing as a visitor: you can read every job here. Sign in or create an account to use them.
Fill in your system's address. The jobs below update as you type.
Your tests. Open one to see it the way it looked live, with its charts, load settings and server usage.
| When | Job | Target | Requests | Avg req/s | p95 | Errors | CPU avg | RAM avg | Result |
|---|
Charts were not recorded for this run (it was saved by an older version).