Skip to demo content
Step 1 of 7: User clicks "Log out" in the app
← All demos

SAML Single Logout with Okta

1. User clicks "Log out" in the app

Alice clicks "Log out". The app destroys its local session immediately, then generates a signed SAML LogoutRequest carrying the NameID, plus the SessionIndex it saved from the original login assertion, and redirects the browser to Okta’s SLO endpoint.

What the user sees

https://secrets.example.com/dashboard
Demo simulation — do not enter real credentials

Create a Secret

Recent Secrets

No secrets created yet

What's happening (HTTP)

  1. REQUEST Browser → App
    POST https://secrets.example.com/logout
    Cookie: _ots_session=encrypted-session-data
    Content-Type: application/x-www-form-urlencoded
    csrf_token=tok_9f8e7d
    Logout must be a POST with CSRF protection -- a GET logout endpoint lets any third-party page log your users out
  2. INTERNAL App → App
    Destroy local session + build LogoutRequest
    Delete server-side session, expire _ots_session cookie. Generate LogoutRequest ID _logout_req_111, store it for InResponseTo validation. Include NameID (alice@contoso.com), which is mandatory, and the optional SessionIndex (_session_okta_ghi789) saved from the login assertion so only this session is targeted.
  3. RESPONSE App → Browser
    302 Found
    Set-Cookie: _ots_session=; Max-Age=0; HttpOnly; Secure
    Location: https://contoso.okta.com/app/ots-saml/exk1234/slo/saml?
    SAMLRequest=base64-deflate-encoded-xml
    &SigAlg=http://www.w3.org/2001/04/xmldsig-more%23rsa-sha256
    &Signature=base64-encoded-signature
    Local session is already dead. Everything after this point is best-effort cleanup of the OTHER sessions.

Legend

Browser request
Server response
Server-to-server
Internal
← All demos
An educational demo, not a reference implementation v0.3.0