Security Assertion Markup Language — XML-based protocol for cross-organization SSO. IdP signs an assertion about the user; SP verifies and lets them in. Backbone of academic federations (eduGAIN, InCommon) and enterprise SSO providers (Okta, Auth0, Ping). SAML 2.0 (2005) is the dominant version.