Here is your SAML2 assertion for EPR INT Emedo Frehner. You can now get a XUA assertion with the Get-X-User-Assertion transaction in your EPR community.
Back to home.
XML inspector
Please be aware that reformatting the assertion makes the signature invalid. Don't try to use this one.
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ID="Assertion_2da17ecc-fbff-4bb5-9556-995591f804a2" IssueInstant="2026-08-31T06:37:19.139Z" Version="2.0">
<saml2:Issuer>urn:oid:2.16.756.5.30.1.191.999.10</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#Assertion_2da17ecc-fbff-4bb5-9556-995591f804a2">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>wX2cSqBNV3+skfCVppCZicr2OhehfNdpl3S5j4RmiY8=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
aKywHxmeG9PPYpSXwDRfzEGQAppdHhOy9QB+DrA4M3CW5PgC9aqezolhhNKrD5oT1UxvWxh+6okM
+ahzWbVfT8a6v704c5UHE1tavl5dOmRY4eyMOisBuz4CKD3RTKJCGdkA/n7SK5D5tP3PTQdWnLVW
KwhPZkmMUvlAdOymYxf8AGONITHSe8U7bDW/5pRxoerpP4KjD8/zvjVNkny8iqo6tfrlZP+9c7pg
m1ZhZ82PqpU/Y5Rtb5Gw8EW+yUDC5w/5UywiAtVxnF+81mVKIq6UFYKXEkafoHKlbE6pbzeAiMNs
LQfvQnXQLPTLUrMhBxRxG7lvtkpCnJQy3dj0h7JEZ6sSvMR+1sACcAlQQpWGQKhKMji0LurIsa7f
dU7+YmnI6y5NN5lv+z/iLoZoZa5cK1e0Tc37fLkmv9v56JjQqpc6sQL9FBFuh20TxNEafM/sU5A5
7qW7/HIwlr16GG/dTARKJT0NzzogStdBbW0bGd3U8IKduYPzAZyw6/xM
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIF8DCCBNigAwIBAgIQCJuEhFy5/LSpywE6V+l76DANBgkqhkiG9w0BAQsFADBTMQswCQYDVQQG
EwJVUzEWMBQGA1UEChMNRGlnaUNlcnQgSW5jLjEsMCoGA1UEAxMjRGlnaUNlcnQgUHJpdmF0ZSBT
U0wgU0hBMjU2IENBIC0gRzIwHhcNMjYwNjI1MDAwMDAwWhcNMjcwNTIzMjM1OTU5WjCBlzELMAkG
A1UEBhMCQ0gxEjAQBgNVBAcTCUVwYWxpbmdlczENMAsGA1UEChMEQ0FSQTEWMBQGA1UECxMNMjAw
MDAxMDY2MDAxODEpMCcGA1UEAwwgdGN1X2NhcmFpa2l0X2x1ZG92aWNfZnJlaG5lcl9pbnQxIjAg
BgkqhkiG9w0BCQEWE2ludGVncmF0aW9uQGNhcmEuY2gwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw
ggGKAoIBgQCqOb+EBmSfSTmyMmZ2h3C3Mlw3LT21qwHK4euyPY2OTgU4NaUAtPnEm9nr/LCF6w6K
IejByq6/8MPWriVA3Jpcl7MmxsdUHOMXIQ+uRMyXQ2MGLiIhjfWhVS0FzZKu09u0NIAZ1ftul1i9
EZr/K7igkZqwrFRWhaEZE1TS2y2KH9xaFEQDnred7gdi4Ez8Im385ZhigUZLKY3Wb/+IBbDqjrMN
/cAMf6JYMSM8UZMtgP1L7gMEJ86CPGoIUhnwtOEPe8y6rtaBtHg1wjBaehWo0gPePsneNbeS8gPa
gEZ3A2X9DhmM/J0WOugHZUbxFbSLrwYq2l5efZNihZCSEnAexA8qBbQD1WZ7Dk/PeSnzo/7oVbmU
Kmg29BNboRespKQIZKjtZee/cE/viV0G0dJT6Jp3NPFMbzpcXfFEcxLfvjEs5W6pbeXL1MI1P2NW
sOPuHEk3gPIrBFmGDdWG/mVooxWyVetTH5G62rKyMhIj4ZwgzG14tZ/3RWp6hUUozJUCAwEAAaOC
AfkwggH1MB8GA1UdIwQYMBaAFFbthhQJehPN3AlzwwPxnbfadisUMB0GA1UdDgQWBBRIz3T/CU2j
JM9vqWKPMDi3r6yC3TAMBgNVHRMBAf8EAjAAMB4GA1UdEQQXMBWBE2ludGVncmF0aW9uQGNhcmEu
Y2gwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDBDBgNVHSAE
PDA6MDgGCmCGSAGG/WwEAQIwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29t
L0NQUzCBjwYDVR0fBIGHMIGEMECgPqA8hjpodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vRGlnaUNl
cnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3JsMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2VydC5j
b20vRGlnaUNlcnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3JsMH8GCCsGAQUFBwEBBHMwcTAkBggr
BgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQuY29tMEkGCCsGAQUFBzAChj1odHRwOi8vY2Fj
ZXJ0cy5kaWdpY2VydC5jb20vRGlnaUNlcnRQcml2YXRlU1NMU0hBMjU2Q0EtRzIuY3J0MA0GCSqG
SIb3DQEBCwUAA4IBAQDMH6geutEfKVGBpmyJ6c/kDiLd60AKZhGjj7tjPRgYTUxmwj8QUfEL5pAU
S6xC8ODaxkP8ZNkhePv/xS43+C8B1hSP0dNNKI7OZ5+nSfFYKzkvm6fonM8NZN3MBJs6qxoFTNwA
7TgZIL96HOsTSIpGLF3KzuujAw+/XPsq4VPTpgp+kItrG4kI5Bwq7sDX2W66hfJqgGgn8PRB+NAa
hs3IgfePwM61zjtILoZkP+xlX39eo9TxE5T7XhFMKw2RfpjF1DK4pcvtrhOOHsMag3r6/YNfqO+S
GuLvX13K/SOD+I9+vuDgZLqJqETPIAZPTJlZrw/oTY3YAwTcHMJEhSjo</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2:Subject>
<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">2.16.756.5.30.1.191.999.10</saml2:NameID>
<saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"/>
</saml2:Subject>
<saml2:Conditions NotBefore="2026-08-31T06:37:19.139Z" NotOnOrAfter="2026-08-31T06:47:19.139Z"/>
<saml2:AuthnStatement AuthnInstant="2026-08-31T06:37:19.139Z" SessionNotOnOrAfter="2026-08-31T06:47:19.139Z">
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
</saml2:Assertion>
How to use
There are two ways to more easily consume this SAML assertion.
-
You can specify the header
Accept: application/xmlwhen requesting this page (GET /tcu/epr_int_emedo_frehner) to receive the assertion XML directly, instead of an HTML page. - You can specify the header
ikit-inject-tcu-token: epr_int_emedo_frehnerin your requests to the IKIT, and it will automatically fetch and inject this SAML assertion before sending your request to its recipient.