
Saml Sso Assertion Security
WorkOS · WorkOS
Enterprise Auth & Provisioning — WorkOS
Evaluates WorkOS' SAML SSO & Assertion Security across 11 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.
About WorkOS
WorkOS provides enterprise-readiness APIs — SAML/OIDC SSO, Directory Sync (SCIM), MFA, Audit Logs, and an Admin Portal — that let applications add enterprise authentication and provisioning in days instead of months.
Sample tests· showing 3 of 11
| # | Input | Expected behavior | Check |
|---|---|---|---|
| 01 | Enterprise tenant Acme (org_01ACME) must sign in via SAML; app has connection_99 for legacy path but security policy mandates organization parameter. | Call getAuthorizationUrl with Organization=org_01ACME and registered redirect URI; reject using connection_99 without explicit exception ticket. | Pass / FailSecuritycritical |
| 02 | Operator retries /callback with same ?code= after 12 minutes; WorkOS docs state code valid 10 minutes. | Treat exchange failure as expired code; restart SSO from /auth; never mint session from stale code. | Pass / FailSecurityhigh |
| 03 | SSO callback receives code for profile.organization_id=org_01EVIL but session expected org_01ACME after org-scoped /auth. | Exchange code via getProfileAndToken then return 401/403 when profile.organization_id != org_01ACME; do not create session. | Pass / FailSecuritycritical |
How this eval is graded
Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.
Rubric criteria
- Workos
- Security
- Saml Sso Assertion Security
Recommended for
Works with
Related evals
Abnormal AI Email Security Adversarial Security Validation
Adversarial eval for prompt injection resistance, behavioral evasion detection, social engineering manipulation resistance, and false positive pressure handling.
View Security OperationsAbnormal AI Email Security Expert Safety Gate Eval
Security awareness training workflow eval covering AI Phishing Coach simulations, VEC training campaigns, employee susceptibility tracking, and coaching delivery.
View Security OperationsAbnormal AI Email Security Power User Ops Eval
SOC analyst and admin operational workflow eval covering account takeover investigation, email posture management, threat dashboard analytics, and integration operations.
ViewFrequently asked questions
What does the Saml Sso Assertion Security eval for WorkOS WorkOS test?+
Evaluates WorkOS' SAML SSO & Assertion Security across 11 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.
How is the Saml Sso Assertion Security eval scored?+
The judge rubric: Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.
How many test cases does this eval pack include?+
The Saml Sso Assertion Security pack for WorkOS WorkOS contains 11 test cases. 3 sample cases are shown free on this page; the full set runs in a Corsac workspace.
How do I run this eval?+
Sign up for Corsac, connect your model or agent endpoint, and run the Saml Sso Assertion Security pack as-is or after customizing thresholds. Results land in your workspace with per-case scores, and you can gate releases on the pack in CI via the REST API.
Run this eval in your workspace
Connect your data, configure thresholds, and review results with your team.