Salesforce supports session index parameters in requests and responses with SAML single
logout (SLO). When a user logs out of a connected app registered for SAML SLO, the session index
parameter is required to identify which user session to end.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
User Permissions Needed
To view the settings:
View Setup and Configuration
To edit the settings:
Customize Application
AND
Modify All Data
As the identity provider, Salesforce generates and sends the session index parameter to the
service provider during SAML single sign-on (SSO). Depending on the application initiating SLO,
one of these processes occurs.
If Salesforce initiates SLO, Salesforce sends the same session index parameter with the
logout request to the service provider.
If the service provider initiates SLO, Salesforce sends the SAML SLO request to the other
service providers participating in the current session. The other service providers post a
logout response to Salesforce. Salesforce then returns the logout response to the initiating
service provider.
As the service provider, Salesforce receives and stores the session index parameter sent from
the identity provider during SSO. If the identity provider initiates SLO, Salesforce sends a
logout response. If Salesforce initiates the SLO, it sends the same session index parameter with
the logout request to the identity provider.
Note If the identity provider sends more than one
session index parameter, Salesforce stores only the first one that it receives. The session
index parameter can’t be more than 512 characters.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.