<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://docs.callproof.com/index.php?action=history&amp;feed=atom&amp;title=SAML_ACS</id>
	<title>SAML ACS - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://docs.callproof.com/index.php?action=history&amp;feed=atom&amp;title=SAML_ACS"/>
	<link rel="alternate" type="text/html" href="http://docs.callproof.com/index.php?title=SAML_ACS&amp;action=history"/>
	<updated>2026-07-24T09:37:23Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.31.0</generator>
	<entry>
		<id>http://docs.callproof.com/index.php?title=SAML_ACS&amp;diff=3857&amp;oldid=prev</id>
		<title>Ashley DeBon: /* SAML Assertion Consumer Service (ACS) */</title>
		<link rel="alternate" type="text/html" href="http://docs.callproof.com/index.php?title=SAML_ACS&amp;diff=3857&amp;oldid=prev"/>
		<updated>2026-07-24T07:16:33Z</updated>

		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;SAML Assertion Consumer Service (ACS)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 07:16, 24 July 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== SAML Assertion Consumer Service (ACS) ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Mobile_API]] &amp;amp;#187;&lt;/ins&gt;SAML Assertion Consumer Service (ACS) ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Base URL ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Base URL ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ashley DeBon</name></author>
		
	</entry>
	<entry>
		<id>http://docs.callproof.com/index.php?title=SAML_ACS&amp;diff=3856&amp;oldid=prev</id>
		<title>Ashley DeBon: Created page with &quot;== SAML Assertion Consumer Service (ACS) ==  === Base URL === https://apimobile.callproof.com  === Endpoint === /api/saml/acs  === Purpose === Receives the Identity Provider (...&quot;</title>
		<link rel="alternate" type="text/html" href="http://docs.callproof.com/index.php?title=SAML_ACS&amp;diff=3856&amp;oldid=prev"/>
		<updated>2026-07-24T07:16:20Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== SAML Assertion Consumer Service (ACS) ==  === Base URL === https://apimobile.callproof.com  === Endpoint === /api/saml/acs  === Purpose === Receives the Identity Provider (...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== SAML Assertion Consumer Service (ACS) ==&lt;br /&gt;
&lt;br /&gt;
=== Base URL ===&lt;br /&gt;
https://apimobile.callproof.com&lt;br /&gt;
&lt;br /&gt;
=== Endpoint ===&lt;br /&gt;
/api/saml/acs&lt;br /&gt;
&lt;br /&gt;
=== Purpose ===&lt;br /&gt;
Receives the Identity Provider (IdP) SAML authentication response after SSO login. Validates the assertion, resolves or provisions the CallProof user, issues a short-lived authorization code, and redirects the mobile app back with either a success code or an error.&lt;br /&gt;
&lt;br /&gt;
This endpoint is called by the IdP (browser POST), not typically by the mobile app directly. Rate limited to 30 requests per minute.&lt;br /&gt;
&lt;br /&gt;
=== HTTP Method ===&lt;br /&gt;
POST&lt;br /&gt;
&lt;br /&gt;
=== Headers ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Header !! Required !! Description&lt;br /&gt;
|-&lt;br /&gt;
| Content-Type || Yes || &amp;lt;code&amp;gt;application/x-www-form-urlencoded&amp;lt;/code&amp;gt; (standard SAML HTTP-POST binding)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Security ===&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;No Bearer token required&amp;#039;&amp;#039;&amp;#039; – This is a public SSO callback endpoint (outside authenticated API middleware).&lt;br /&gt;
* Protected by request throttling (&amp;lt;code&amp;gt;30&amp;lt;/code&amp;gt; requests per minute).&lt;br /&gt;
* SAML response signature/assertion validation is enforced by the SSO service configuration.&lt;br /&gt;
&lt;br /&gt;
=== Parameters ===&lt;br /&gt;
&lt;br /&gt;
==== Path Parameters ====&lt;br /&gt;
None.&lt;br /&gt;
&lt;br /&gt;
==== Query Parameters ====&lt;br /&gt;
None.&lt;br /&gt;
&lt;br /&gt;
==== Request Body ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Parameter !! Type !! Required !! Description&lt;br /&gt;
|-&lt;br /&gt;
| SAMLResponse || string || Yes || Base64-encoded SAML authentication response from the IdP&lt;br /&gt;
|-&lt;br /&gt;
| RelayState || string || No || Mobile redirect / callback target used to return the user to the app after SSO. If omitted or invalid, the configured default mobile redirect is used&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Successful Response (302 Redirect) ===&lt;br /&gt;
On success, the API does &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; return JSON. It redirects the mobile app callback URL with an authorization code.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Type !! Description&lt;br /&gt;
|-&lt;br /&gt;
| HTTP status || integer || Redirect (typically 302)&lt;br /&gt;
|-&lt;br /&gt;
| Location || string || Mobile callback URL with query parameter &amp;lt;code&amp;gt;code&amp;lt;/code&amp;gt; (authorization code to exchange for an access token via the SAML login endpoint)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Example callback shape: mobile redirect URL with &amp;lt;code&amp;gt;?code={authorization_code}&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Error Responses ===&lt;br /&gt;
Errors are also returned as redirects to the mobile callback URL (not typical JSON API error bodies), with query parameters:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Query Parameter !! Description&lt;br /&gt;
|-&lt;br /&gt;
| error || Error key (for example, &amp;quot;Authentication failed&amp;quot; or &amp;quot;User not found&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
| message || Human-readable error detail&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Common error cases:&lt;br /&gt;
&lt;br /&gt;
* Missing &amp;lt;code&amp;gt;SAMLResponse&amp;lt;/code&amp;gt; — message: &amp;quot;SAMLResponse parameter is missing from the request&amp;quot;&lt;br /&gt;
* Expired/invalid SSO session (RelayState/authn request) — message: &amp;quot;SSO session expired or invalid. Please try again.&amp;quot;&lt;br /&gt;
* Invalid SAML assertion — message: &amp;quot;SSO authentication failed. Please try again.&amp;quot;&lt;br /&gt;
* No email/user identifier in SAML response — message: &amp;quot;SSO login failed: no valid email address in SAML response.&amp;quot;&lt;br /&gt;
* User not found in CallProof — error: &amp;quot;User not found&amp;quot;, message: &amp;quot;User not found in CallProof&amp;quot;&lt;br /&gt;
* Authorization code could not be issued — message: &amp;quot;SSO authentication failed. Please try again.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Status Code !! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| 302 || Redirect to mobile app with &amp;lt;code&amp;gt;code&amp;lt;/code&amp;gt; (success) or &amp;lt;code&amp;gt;error&amp;lt;/code&amp;gt;/&amp;lt;code&amp;gt;message&amp;lt;/code&amp;gt; (failure)&lt;br /&gt;
|-&lt;br /&gt;
| 429 || Too Many Requests – throttle limit exceeded (30 requests/minute)&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ashley DeBon</name></author>
		
	</entry>
</feed>