BerriAI/litellm · error · HTTPException

SAML response is not bound to this browser's login request.

Error message

SAML response is not bound to this browser's login request.

What it means

The response references a known AuthnRequest, but the browser's state cookie does not match the InResponseTo id (constant-time compare fails or cookie is missing): the SAML response was delivered in a different browser session than the one that started login. Raised as 401.

Source

Thrown at litellm/proxy/management_endpoints/sso/saml_sso.py:375

        return None

    @staticmethod
    async def _enforce_response_binding(
        auth: "OneLogin_Saml2_Auth",
        cache: DualCache,
        browser_request_id: str | None,
    ) -> None:
        in_response_to: Final = SAMLAuthHandler._response_in_response_to(auth)

        if in_response_to is not None:
            authn_key: Final = f"{_SAML_AUTHN_REQUEST_CACHE_PREFIX}:{in_response_to}"
            if cache.get_cache(key=authn_key) is None:
                raise HTTPException(
                    status_code=status.HTTP_401_UNAUTHORIZED,
                    detail="SAML response references an unknown or already-used login request.",
                )
            if browser_request_id is None or not secrets.compare_digest(browser_request_id, in_response_to):
                raise HTTPException(
                    status_code=status.HTTP_401_UNAUTHORIZED,
                    detail="SAML response is not bound to this browser's login request.",
                )
        elif browser_request_id is not None:
            raise HTTPException(
                status_code=status.HTTP_401_UNAUTHORIZED,
                detail="SAML response is not bound to this browser's login request.",
            )
        elif not SAMLAuthHandler._bool_env("SAML_ALLOW_UNSOLICITED", False):
            raise HTTPException(
                status_code=status.HTTP_401_UNAUTHORIZED,
                detail="Unsolicited (IdP-initiated) SAML responses are disabled.",
            )
        elif cache.redis_cache is None:
            raise HTTPException(
                status_code=status.HTTP_401_UNAUTHORIZED,
                detail=(
                    "Unsolicited (IdP-initiated) SAML responses require a shared Redis cache "

View on GitHub (pinned to 77b7c6c40c)

Solutions

  1. Complete the login in the same browser session that started it (cookies required).
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at litellm/proxy/management_endpoints/sso/saml_sso.py:375 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of BerriAI/litellm@77b7c6c40c (2026-08-18). Data as JSON: /api/errors/466e3eb940cf3f19. Report an issue: GitHub.