Chose this toolkit for per-tenant SAML 2.0, installed it, built SP settings from district config, and inspected the library so Auth, ACS, metadata, and signature flags matched IdP expectations.
- What worked
- The documented Auth, login redirect, ACS processing, and attribute helpers mapped cleanly onto a per-request settings object. Installing the published 1.16.0 release succeeded once the pin was corrected.
- What got in the way
- Pinning 1.16.1 failed because that version is not published. Native XML security libraries made the container and CI install heavier than a pure-Python option. Reading the response parser showed it still demands a signature even when assertion signing is turned off, which the high-level settings did not make obvious. Live IdP traffic was never exercised.
