Single Logout

The APS Identity protocol includes the SAML Single Logout protocol. For details on the protocol, refer to the SAML Specification, Section 3.7.

For details on implementation of the protocol, refer to the 4.4 Single Logout Profile section of the Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0 document.

The APS Identity protocol supports HTTP POST binding model to transport logout-related messages between IdP and SPs. For details on the model, refer to the 3.5 HTTP POST Binding section of the Bindings for the OASIS Security Assertion Markup Language (SAML) V2.0 document.

Remarks

All SAML messages from SPs are sent to URL IDP_API_BASE_URL/signout.

All SAML messages from IdP are sent to URL SP_API_BASE_URL/SAML.