IdP-initiated Single Sign-On

A SAMLRequest is sent to the Identity Provider, customer authenticates against the SAML Identity Provider and then information about the user, group and address are sent to Magento in a SAMLResponse, Magento SAML extension validates the SAMLResponse, authenticate customer (provisioning a new account if required and the feature is enabled) and let him in.

SP-initiated Single Sign-On

Like the previous scenario, but here the SAML Response is directly sent by the Identity Provider and processed by the Magento SAML extension.

SP-initiated Single Logout

A SAML Logout Request is sent to the Identity Provider, the IdP close its session and the session of other related Service Providers and sent back a Logout Response to the Magento instance that will close the session.

IdP-initiated Single Logout

A SAML Logout Request is sent by the Identity Provider, the Magento instance validates it, close its session and reply back a SAML Logout Response.