BLASTA

SAML service provider load testing template

What the SP does per request: session check, redirect to the IdP, ACS handling, metadata and logout.

Category SAMLStack Shibboleth SP, mod_auth_mellon, SimpleSAMLphp SP, Spring Security SAMLJobs 25

About this SAML service provider load test

Load tests a SAML service provider such as Shibboleth SP, mod_auth_mellon, SimpleSAMLphp SP or Spring Security SAML: SP metadata, a public page, a protected page without a session (the redirect to the IdP), the login handler, session status, assertion consumer calls with garbage or empty data, logout and an unauthenticated ramp.

It holds 25 ready-made jobs: 9 single scenarios and an enterprise test plan of 16 stages to run in order, 13 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.

Scenarios include SP metadata, public page behind the SP, protected page without a session, SP login handler and session status.

How to load test SAML service provider

  1. Open the template in BLASTA.
  2. Set url to point at your own SAML service provider system, ideally a staging copy.
  3. Pick a job and choose the rate and duration.
  4. Start the run and watch requests per second, latency percentiles and errors live; the result is saved to your history.

What you set before running

url
SP base URL, no trailing slash
protectedPath
A path protected by the SP
publicPath
A public path on the same site
metadataPath
SP metadata path
acsPath
Assertion consumer service path
sessionPath
SP session status path
loginPath
SP login handler path
logoutPath
SP logout handler path

Test scenarios (9)

SP metadata

Read-only

Fetched by IdPs, federations and monitoring.

protected page without a session

Read-only

The SP builds an AuthnRequest and redirects to the IdP. This is every new visitor's first request. Redirects are not followed.

session status

Read-only

Polled by SPAs to see whether the user is logged in.

ACS with a garbage SAMLResponse

Read-only

Anyone can POST to the ACS URL. The SP must reject an invalid response cheaply (no signature check should run) and without crashing. A 4xx or the SP's error page counts as rejected.

unauthenticated traffic ramp

Read-only

Ramps requests to a protected page to find where the SP and its session store slow down. Each request creates a session or a redirect record.

Enterprise test plan (16)

Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.

Frequently asked questions

What does the SAML service provider load test cover?

The SAML service provider template has 25 jobs: 9 single scenarios and an enterprise test plan of 16 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include SP metadata, public page behind the SP, protected page without a session and SP login handler. 13 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.

How do I load test SAML service provider with BLASTA?

Open the template in BLASTA and set url, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new saml-sp with your address.

Is it safe to run the SAML service provider load test against production?

All 25 jobs in this template are read-only: they request pages or data and do not change anything. Even so, a load test can slow a live system down, so start with a low rate and prefer a staging copy. Only test systems you own or have permission to test.

Related templates

Run a load test

Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.

1 What do you want to test? Use a template

Request headers

2 How hard should it hit?

Advanced limits
Pass / fail targets (SLO) optional
The result is marked SLO met or SLO missed. The same targets live in a job file, where blasta run exits 2 on a miss so CI or Kubernetes can gate a release.

Set up this job

Quick check

Please confirm you are not a robot to start your free test.

Clear history

Delete every finished test in your history. Tests still running are kept. This cannot be undone.

Add identity provider

Add user

The account is active at once. Share the password with them securely; they can change it from their menu.

Sign in to use templates

Templates and test history are part of the full app. Sign in, or create a free account, to use them.

Sign inCreate account

Change password