Integration  KIT IDP

Here is your SAML2 assertion for EPR INT Emedo Frehner. You can now get a XUA assertion with the Get-X-User-Assertion transaction in your EPR community.

Back to home.

XML inspector

Please be aware that reformatting the assertion makes the signature invalid. Don't try to use this one.

<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ID="Assertion_2da17ecc-fbff-4bb5-9556-995591f804a2" IssueInstant="2026-08-31T06:37:19.139Z" Version="2.0">
  <saml2:Issuer>urn:oid:2.16.756.5.30.1.191.999.10</saml2:Issuer>
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
      <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
      <ds:Reference URI="#Assertion_2da17ecc-fbff-4bb5-9556-995591f804a2">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
          <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
        <ds:DigestValue>wX2cSqBNV3+skfCVppCZicr2OhehfNdpl3S5j4RmiY8=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>
aKywHxmeG9PPYpSXwDRfzEGQAppdHhOy9QB+DrA4M3CW5PgC9aqezolhhNKrD5oT1UxvWxh+6okM&#13;
+ahzWbVfT8a6v704c5UHE1tavl5dOmRY4eyMOisBuz4CKD3RTKJCGdkA/n7SK5D5tP3PTQdWnLVW&#13;
KwhPZkmMUvlAdOymYxf8AGONITHSe8U7bDW/5pRxoerpP4KjD8/zvjVNkny8iqo6tfrlZP+9c7pg&#13;
m1ZhZ82PqpU/Y5Rtb5Gw8EW+yUDC5w/5UywiAtVxnF+81mVKIq6UFYKXEkafoHKlbE6pbzeAiMNs&#13;
LQfvQnXQLPTLUrMhBxRxG7lvtkpCnJQy3dj0h7JEZ6sSvMR+1sACcAlQQpWGQKhKMji0LurIsa7f&#13;
dU7+YmnI6y5NN5lv+z/iLoZoZa5cK1e0Tc37fLkmv9v56JjQqpc6sQL9FBFuh20TxNEafM/sU5A5&#13;
7qW7/HIwlr16GG/dTARKJT0NzzogStdBbW0bGd3U8IKduYPzAZyw6/xM
</ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <ds:X509Certificate>MIIF8DCCBNigAwIBAgIQCJuEhFy5/LSpywE6V+l76DANBgkqhkiG9w0BAQsFADBTMQswCQYDVQQG
EwJVUzEWMBQGA1UEChMNRGlnaUNlcnQgSW5jLjEsMCoGA1UEAxMjRGlnaUNlcnQgUHJpdmF0ZSBT
U0wgU0hBMjU2IENBIC0gRzIwHhcNMjYwNjI1MDAwMDAwWhcNMjcwNTIzMjM1OTU5WjCBlzELMAkG
A1UEBhMCQ0gxEjAQBgNVBAcTCUVwYWxpbmdlczENMAsGA1UEChMEQ0FSQTEWMBQGA1UECxMNMjAw
MDAxMDY2MDAxODEpMCcGA1UEAwwgdGN1X2NhcmFpa2l0X2x1ZG92aWNfZnJlaG5lcl9pbnQxIjAg
BgkqhkiG9w0BCQEWE2ludGVncmF0aW9uQGNhcmEuY2gwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw
ggGKAoIBgQCqOb+EBmSfSTmyMmZ2h3C3Mlw3LT21qwHK4euyPY2OTgU4NaUAtPnEm9nr/LCF6w6K
IejByq6/8MPWriVA3Jpcl7MmxsdUHOMXIQ+uRMyXQ2MGLiIhjfWhVS0FzZKu09u0NIAZ1ftul1i9
EZr/K7igkZqwrFRWhaEZE1TS2y2KH9xaFEQDnred7gdi4Ez8Im385ZhigUZLKY3Wb/+IBbDqjrMN
/cAMf6JYMSM8UZMtgP1L7gMEJ86CPGoIUhnwtOEPe8y6rtaBtHg1wjBaehWo0gPePsneNbeS8gPa
gEZ3A2X9DhmM/J0WOugHZUbxFbSLrwYq2l5efZNihZCSEnAexA8qBbQD1WZ7Dk/PeSnzo/7oVbmU
Kmg29BNboRespKQIZKjtZee/cE/viV0G0dJT6Jp3NPFMbzpcXfFEcxLfvjEs5W6pbeXL1MI1P2NW
sOPuHEk3gPIrBFmGDdWG/mVooxWyVetTH5G62rKyMhIj4ZwgzG14tZ/3RWp6hUUozJUCAwEAAaOC
AfkwggH1MB8GA1UdIwQYMBaAFFbthhQJehPN3AlzwwPxnbfadisUMB0GA1UdDgQWBBRIz3T/CU2j
JM9vqWKPMDi3r6yC3TAMBgNVHRMBAf8EAjAAMB4GA1UdEQQXMBWBE2ludGVncmF0aW9uQGNhcmEu
Y2gwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDBDBgNVHSAE
PDA6MDgGCmCGSAGG/WwEAQIwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29t
L0NQUzCBjwYDVR0fBIGHMIGEMECgPqA8hjpodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vRGlnaUNl
cnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3JsMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2VydC5j
b20vRGlnaUNlcnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3JsMH8GCCsGAQUFBwEBBHMwcTAkBggr
BgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQuY29tMEkGCCsGAQUFBzAChj1odHRwOi8vY2Fj
ZXJ0cy5kaWdpY2VydC5jb20vRGlnaUNlcnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3J0MA0GCSqG
SIb3DQEBCwUAA4IBAQDMH6geutEfKVGBpmyJ6c/kDiLd60AKZhGjj7tjPRgYTUxmwj8QUfEL5pAU
S6xC8ODaxkP8ZNkhePv/xS43+C8B1hSP0dNNKI7OZ5+nSfFYKzkvm6fonM8NZN3MBJs6qxoFTNwA
7TgZIL96HOsTSIpGLF3KzuujAw+/XPsq4VPTpgp+kItrG4kI5Bwq7sDX2W66hfJqgGgn8PRB+NAa
hs3IgfePwM61zjtILoZkP+xlX39eo9TxE5T7XhFMKw2RfpjF1DK4pcvtrhOOHsMag3r6/YNfqO+S
GuLvX13K/SOD+I9+vuDgZLqJqETPIAZPTJlZrw/oTY3YAwTcHMJEhSjo</ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <saml2:Subject>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">2.16.756.5.30.1.191.999.10</saml2:NameID>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"/>
  </saml2:Subject>
  <saml2:Conditions NotBefore="2026-08-31T06:37:19.139Z" NotOnOrAfter="2026-08-31T06:47:19.139Z"/>
  <saml2:AuthnStatement AuthnInstant="2026-08-31T06:37:19.139Z" SessionNotOnOrAfter="2026-08-31T06:47:19.139Z">
    <saml2:AuthnContext>
      <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml2:AuthnContextClassRef>
    </saml2:AuthnContext>
  </saml2:AuthnStatement>
</saml2:Assertion>
How to use

There are two ways to more easily consume this SAML assertion.

  1. You can specify the header Accept: application/xml when requesting this page (GET /tcu/epr_int_emedo_frehner) to receive the assertion XML directly, instead of an HTML page.
  2. You can specify the header ikit-inject-tcu-token: epr_int_emedo_frehner in your requests to the IKIT, and it will automatically fetch and inject this SAML assertion before sending your request to its recipient.