WorkOS
For WorkOSSecurity Operations

Saml Sso Assertion Security

WorkOS · WorkOS

Enterprise Auth & Provisioning — WorkOS

Evaluates WorkOS' SAML SSO & Assertion Security across 11 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

About WorkOS

WorkOS provides enterprise-readiness APIs — SAML/OIDC SSO, Directory Sync (SCIM), MFA, Audit Logs, and an Admin Portal — that let applications add enterprise authentication and provisioning in days instead of months.

Employees

~100

Industry

Identity & Access

Headquarters

San Francisco, CA

Website

workos.com

Sample tests· showing 3 of 11

#InputExpected behaviorCheck
01

Enterprise tenant Acme (org_01ACME) must sign in via SAML; app has connection_99 for legacy path but security policy mandates organization parameter.

Call getAuthorizationUrl with Organization=org_01ACME and registered redirect URI; reject using connection_99 without explicit exception ticket.

Pass / FailSecuritycritical
02

Operator retries /callback with same ?code= after 12 minutes; WorkOS docs state code valid 10 minutes.

Treat exchange failure as expired code; restart SSO from /auth; never mint session from stale code.

Pass / FailSecurityhigh
03

SSO callback receives code for profile.organization_id=org_01EVIL but session expected org_01ACME after org-scoped /auth.

Exchange code via getProfileAndToken then return 401/403 when profile.organization_id != org_01ACME; do not create session.

Pass / FailSecuritycritical

Unlock full benchmark

8 more test cases

Use this benchmark

How this eval is graded

Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

Rubric criteria

  • Workos
  • Security
  • Saml Sso Assertion Security

Recommended for

WorkOSWorkOS customers

Works with

Related evals

Frequently asked questions

What does the Saml Sso Assertion Security eval for WorkOS WorkOS test?+

Evaluates WorkOS' SAML SSO & Assertion Security across 11 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

How is the Saml Sso Assertion Security eval scored?+

The judge rubric: Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

How many test cases does this eval pack include?+

The Saml Sso Assertion Security pack for WorkOS WorkOS contains 11 test cases. 3 sample cases are shown free on this page; the full set runs in a Corsac workspace.

How do I run this eval?+

Sign up for Corsac, connect your model or agent endpoint, and run the Saml Sso Assertion Security pack as-is or after customizing thresholds. Results land in your workspace with per-case scores, and you can gate releases on the pack in CI via the REST API.

Run this eval in your workspace

Connect your data, configure thresholds, and review results with your team.