> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iotools.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML Response Decoder

> Decode a base64-encoded SAML Response or Assertion and inspect it. Auto-detects the HTTP-POST (plain base64) and HTTP-Redirect (DEFLATE-compressed) bindings, extracts a summary of key fields (Issuer, Destination, NameID, Conditions window, AudienceRestriction, attributes, StatusCode) and pretty-prints the decoded XML. A debugging tool for SSO troubleshooting — it does not verify signatures.

[Try SAML Response Decoder in your browser →](https://iotools.cloud/tool/saml-response-decoder/)



## OpenAPI

````yaml https://api.iotools.cloud/v1/openapi post /v1/tool/saml-response-decoder
openapi: 3.1.0
info:
  title: iotools.cloud API
  version: 1.0.0
  description: >-
    Run any iotools.cloud tool over HTTP.


    Authenticate with `Authorization: Bearer iot_live_…`.


    **Only `POST /v1/tool/{slug}` costs credits.** Every GET here — the catalog,
    a tool's schema, your balance — is free. A tool call is charged its own
    weight or your plan's per-call minimum, whichever is larger;
    `x-iotools-credit-cost` on each operation is quoted at the free-tier
    minimum, and `GET /v1/tools/list` returns the exact figure for your key.
    `GET /v1/me/credits` reports what you have left, and `GET /v1/me/usage`
    reports what it went on.


    Failures are RFC 9457 problem documents — branch on `code`.
servers:
  - url: https://api.iotools.cloud
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Catalog
    description: Find a tool and read its contract. Free.
  - name: Converters
    description: >-
      Convert between formats, encodings, and units — Base64, CSV and JSON,
      timestamps, and more. Fast, free, and processed right in your browser.
  - name: Formatters
    description: >-
      Format, beautify, minify, and validate code and data — JSON, HTML, CSS,
      SQL, and regex. Clean up messy input in one click, with nothing to upload.
  - name: Generators
    description: >-
      Generate exactly what you need and on demand — passwords, UUIDs, QR codes,
      hashes, random numbers, and more. Secure, instant, and free.
  - name: Calculators
    description: >-
      Crunch the numbers fast — from everyday math to specialized conversions
      and unit work. Free online calculators that run entirely in your browser.
  - name: Editors
    description: >-
      Edit and transform text, code, and images with quick, focused editors that
      run entirely in your browser — nothing to install, and no sign-up needed.
  - name: Utilities
    description: >-
      Everyday developer and web utilities — DNS and IP lookups, redirect and
      certificate checkers, and other quick diagnostics. Free and
      privacy-friendly.
  - name: Account
    description: Your key's allowance, limits and usage history.
paths:
  /v1/tool/saml-response-decoder:
    post:
      tags:
        - Utilities
      summary: SAML Response Decoder
      description: >-
        Decode a base64-encoded SAML Response or Assertion and inspect it.
        Auto-detects the HTTP-POST (plain base64) and HTTP-Redirect
        (DEFLATE-compressed) bindings, extracts a summary of key fields (Issuer,
        Destination, NameID, Conditions window, AudienceRestriction, attributes,
        StatusCode) and pretty-prints the decoded XML. A debugging tool for SSO
        troubleshooting — it does not verify signatures.


        [Try SAML Response Decoder in your browser
        →](https://iotools.cloud/tool/saml-response-decoder/)
      operationId: run_saml_response_decoder
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                samlInput:
                  type: string
                  description: SAML Response or Assertion
                referenceTime:
                  type: string
                  description: Reference Time (now)
              required: []
            examples:
              http_post_binding_full_saml_response_with_assertion:
                summary: HTTP-POST binding — full SAML Response with assertion
                value:
                  samlInput: >-
                    PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48c2FtbHA6UmVzcG9uc2UgeG1sbnM6c2FtbHA9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpwcm90b2NvbCIgeG1sbnM6c2FtbD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFzc2VydGlvbiIgSUQ9Il84ZThkYzVmNi1iNTdhLTRlZDktYTRmYy01MGY5MmI3YjVmZTEiIFZlcnNpb249IjIuMCIgSXNzdWVJbnN0YW50PSIyMDI0LTAxLTE1VDEwOjMwOjAwWiIgRGVzdGluYXRpb249Imh0dHBzOi8vc3AuZXhhbXBsZS5jb20vU1NPL1BPU1QiIEluUmVzcG9uc2VUbz0iX3JlcWlkXzk5ODgiPjxzYW1sOklzc3Vlcj5odHRwczovL2lkcC5leGFtcGxlLmNvbS9TU088L3NhbWw6SXNzdWVyPjxzYW1scDpTdGF0dXM+PHNhbWxwOlN0YXR1c0NvZGUgVmFsdWU9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpzdGF0dXM6U3VjY2VzcyIvPjwvc2FtbHA6U3RhdHVzPjxzYW1sOkFzc2VydGlvbiBJRD0iX2Q3MWEzYThlOWZjYzQ1YzllOWQyNDhlZjcwNDkzOTNmIiBWZXJzaW9uPSIyLjAiIElzc3VlSW5zdGFudD0iMjAyNC0wMS0xNVQxMDozMDowMFoiPjxzYW1sOklzc3Vlcj5odHRwczovL2lkcC5leGFtcGxlLmNvbS9TU088L3NhbWw6SXNzdWVyPjxzYW1sOlN1YmplY3Q+PHNhbWw6TmFtZUlEIEZvcm1hdD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6MS4xOm5hbWVpZC1mb3JtYXQ6ZW1haWxBZGRyZXNzIj51c2VyQGV4YW1wbGUuY29tPC9zYW1sOk5hbWVJRD48c2FtbDpTdWJqZWN0Q29uZmlybWF0aW9uIE1ldGhvZD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmNtOmJlYXJlciI+PHNhbWw6U3ViamVjdENvbmZpcm1hdGlvbkRhdGEgTm90T25PckFmdGVyPSIyMDI0LTAxLTE1VDEwOjM1OjAwWiIgUmVjaXBpZW50PSJodHRwczovL3NwLmV4YW1wbGUuY29tL1NTTy9QT1NUIi8+PC9zYW1sOlN1YmplY3RDb25maXJtYXRpb24+PC9zYW1sOlN1YmplY3Q+PHNhbWw6Q29uZGl0aW9ucyBOb3RCZWZvcmU9IjIwMjQtMDEtMTVUMTA6MjU6MDBaIiBOb3RPbk9yQWZ0ZXI9IjIwMjQtMDEtMTVUMTA6MzU6MDBaIj48c2FtbDpBdWRpZW5jZVJlc3RyaWN0aW9uPjxzYW1sOkF1ZGllbmNlPmh0dHBzOi8vc3AuZXhhbXBsZS5jb208L3NhbWw6QXVkaWVuY2U+PC9zYW1sOkF1ZGllbmNlUmVzdHJpY3Rpb24+PC9zYW1sOkNvbmRpdGlvbnM+PHNhbWw6QXV0aG5TdGF0ZW1lbnQgQXV0aG5JbnN0YW50PSIyMDI0LTAxLTE1VDEwOjMwOjAwWiIgU2Vzc2lvbkluZGV4PSJfc2Vzc2lvbl9pZF8wMDEiPjxzYW1sOkF1dGhuQ29udGV4dD48c2FtbDpBdXRobkNvbnRleHRDbGFzc1JlZj51cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6YWM6Y2xhc3NlczpQYXNzd29yZFByb3RlY3RlZFRyYW5zcG9ydDwvc2FtbDpBdXRobkNvbnRleHRDbGFzc1JlZj48L3NhbWw6QXV0aG5Db250ZXh0Pjwvc2FtbDpBdXRoblN0YXRlbWVudD48c2FtbDpBdHRyaWJ1dGVTdGF0ZW1lbnQ+PHNhbWw6QXR0cmlidXRlIE5hbWU9IkVtYWlsIj48c2FtbDpBdHRyaWJ1dGVWYWx1ZT51c2VyQGV4YW1wbGUuY29tPC9zYW1sOkF0dHJpYnV0ZVZhbHVlPjwvc2FtbDpBdHRyaWJ1dGU+PHNhbWw6QXR0cmlidXRlIE5hbWU9IkZpcnN0TmFtZSI+PHNhbWw6QXR0cmlidXRlVmFsdWU+Sm9objwvc2FtbDpBdHRyaWJ1dGVWYWx1ZT48L3NhbWw6QXR0cmlidXRlPjxzYW1sOkF0dHJpYnV0ZSBOYW1lPSJMYXN0TmFtZSI+PHNhbWw6QXR0cmlidXRlVmFsdWU+RG9lPC9zYW1sOkF0dHJpYnV0ZVZhbHVlPjwvc2FtbDpBdHRyaWJ1dGU+PC9zYW1sOkF0dHJpYnV0ZVN0YXRlbWVudD48L3NhbWw6QXNzZXJ0aW9uPjwvc2FtbHA6UmVzcG9uc2U+
                  referenceTime: '2024-01-15T10:30:00Z'
              http_redirect_binding_deflate_compressed_authnrequest:
                summary: HTTP-Redirect binding — DEFLATE-compressed AuthnRequest
                value:
                  samlInput: >-
                    fVHLbsIwEPwVy/c86aGySFAEQkKiDxHooRfk2ttiyY/gdSj9+7qhqHCg0p52Z2ZnZ8eTo9HkAB6VsxUt0pwSsMJJZT8qulnPk3s6qcfIje5Y04edXcG+Bwwk8iyyYVDR3lvmOCpklhtAFgRrm4clK9Ocdd4FJ5ymF5T/GRwRfIiGKFnMKrr1sN/yN1GUI0pezlYjMI4Re1hYDNyG2MrLuyQfJXmxLkqW57FeKZlFt8ryH72K7kLokGWZkl0KR246DalwJmvbp2wFUnkQgZLmbGDqLPYGfAv+oARsVss/CbxW4ALpKSg2uPL1DaCBwCUPfJxdgn8jfoxhLGbPTivxRebOGx7vupVVkRZDR8nkfYAyMFzpRkoPiPEMrd3n1AMPUNHge6BZfdp6/cv6Gw==
                  referenceTime: ''
              failed_status_response_statuscode_not_success:
                summary: Failed-status Response (StatusCode not Success)
                value:
                  samlInput: >-
                    PHNhbWxwOlJlc3BvbnNlIHhtbG5zOnNhbWxwPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6cHJvdG9jb2wiIHhtbG5zOnNhbWw9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDphc3NlcnRpb24iIElEPSJfZmFpbF8xIiBWZXJzaW9uPSIyLjAiIElzc3VlSW5zdGFudD0iMjAyNC0wNS0wMVQwODowMDowMFoiIERlc3RpbmF0aW9uPSJodHRwczovL3NwLmV4YW1wbGUuY29tL2FjcyI+PHNhbWw6SXNzdWVyPmh0dHBzOi8vaWRwLmV4YW1wbGUuY29tL1NTTzwvc2FtbDpJc3N1ZXI+PHNhbWxwOlN0YXR1cz48c2FtbHA6U3RhdHVzQ29kZSBWYWx1ZT0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOnN0YXR1czpSZXNwb25kZXIiLz48c2FtbHA6U3RhdHVzTWVzc2FnZT5BdXRoZW50aWNhdGlvbiBmYWlsZWQ8L3NhbWxwOlN0YXR1c01lc3NhZ2U+PC9zYW1scDpTdGF0dXM+PC9zYW1scDpSZXNwb25zZT4=
                  referenceTime: '2024-05-01T08:00:00Z'
              malformed_input_handled_gracefully:
                summary: Malformed input (handled gracefully)
                value:
                  samlInput: this is definitely not a SAML response
                  referenceTime: ''
      responses:
        '200':
          description: Tool output
          content:
            application/json:
              examples:
                http_post_binding_full_saml_response_with_assertion:
                  summary: HTTP-POST binding — full SAML Response with assertion
                  value:
                    tool: saml-response-decoder
                    tool_version: 1.0.1
                    outputs:
                      notes:
                        - level: Binding
                          message: HTTP-POST (plain base64, no compression)
                        - level: OK
                          message: >-
                            Assertion is within its validity window at the
                            reference time.
                        - level: Signature
                          message: No XML signature element found in this document.
                      summary:
                        - field: Document Type
                          value: Response
                        - field: ID
                          value: _8e8dc5f6-b57a-4ed9-a4fc-50f92b7b5fe1
                        - field: Version
                          value: '2.0'
                        - field: IssueInstant
                          value: '2024-01-15T10:30:00Z'
                        - field: Destination
                          value: https://sp.example.com/SSO/POST
                        - field: InResponseTo
                          value: _reqid_9988
                        - field: Issuer
                          value: https://idp.example.com/SSO
                        - field: StatusCode
                          value: urn:oasis:names:tc:SAML:2.0:status:Success
                        - field: NameID
                          value: user@example.com
                        - field: NameID Format
                          value: >-
                            urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
                        - field: Conditions NotBefore
                          value: '2024-01-15T10:25:00Z'
                        - field: Conditions NotOnOrAfter
                          value: '2024-01-15T10:35:00Z'
                        - field: Audience
                          value: https://sp.example.com
                        - field: Recipient
                          value: https://sp.example.com/SSO/POST
                        - field: SubjectConfirmation NotOnOrAfter
                          value: '2024-01-15T10:35:00Z'
                        - field: AuthnInstant
                          value: '2024-01-15T10:30:00Z'
                        - field: SessionIndex
                          value: _session_id_001
                        - field: AuthnContextClassRef
                          value: >-
                            urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
                        - field: 'Attribute: Email'
                          value: user@example.com
                        - field: 'Attribute: FirstName'
                          value: John
                        - field: 'Attribute: LastName'
                          value: Doe
                      xml: >-
                        <?xml version="1.0" encoding="UTF-8"?>

                        <samlp:Response
                        xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                        ID="_8e8dc5f6-b57a-4ed9-a4fc-50f92b7b5fe1" Version="2.0"
                        IssueInstant="2024-01-15T10:30:00Z"
                        Destination="https://sp.example.com/SSO/POST"
                        InResponseTo="_reqid_9988">
                          <saml:Issuer>https://idp.example.com/SSO</saml:Issuer>
                          <samlp:Status>
                            <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
                          </samlp:Status>
                          <saml:Assertion ID="_d71a3a8e9fcc45c9e9d248ef7049393f" Version="2.0" IssueInstant="2024-01-15T10:30:00Z">
                            <saml:Issuer>https://idp.example.com/SSO</saml:Issuer>
                            <saml:Subject>
                              <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@example.com</saml:NameID>
                              <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                                <saml:SubjectConfirmationData NotOnOrAfter="2024-01-15T10:35:00Z" Recipient="https://sp.example.com/SSO/POST"/>
                              </saml:SubjectConfirmation>
                            </saml:Subject>
                            <saml:Conditions NotBefore="2024-01-15T10:25:00Z" NotOnOrAfter="2024-01-15T10:35:00Z">
                              <saml:AudienceRestriction>
                                <saml:Audience>https://sp.example.com</saml:Audience>
                              </saml:AudienceRestriction>
                            </saml:Conditions>
                            <saml:AuthnStatement AuthnInstant="2024-01-15T10:30:00Z" SessionIndex="_session_id_001">
                              <saml:AuthnContext>
                                <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef>
                              </saml:AuthnContext>
                            </saml:AuthnStatement>
                            <saml:AttributeStatement>
                              <saml:Attribute Name="Email">
                                <saml:AttributeValue>user@example.com</saml:AttributeValue>
                              </saml:Attribute>
                              <saml:Attribute Name="FirstName">
                                <saml:AttributeValue>John</saml:AttributeValue>
                              </saml:Attribute>
                              <saml:Attribute Name="LastName">
                                <saml:AttributeValue>Doe</saml:AttributeValue>
                              </saml:Attribute>
                            </saml:AttributeStatement>
                          </saml:Assertion>
                        </samlp:Response>
                    credits_used: 3
                    credits_remaining: null
                http_redirect_binding_deflate_compressed_authnrequest:
                  summary: HTTP-Redirect binding — DEFLATE-compressed AuthnRequest
                  value:
                    tool: saml-response-decoder
                    tool_version: 1.0.1
                    outputs:
                      notes:
                        - level: Binding
                          message: HTTP-Redirect (raw DEFLATE compressed)
                        - level: Signature
                          message: No XML signature element found in this document.
                      summary:
                        - field: Document Type
                          value: AuthnRequest
                        - field: ID
                          value: _req_abc123
                        - field: Version
                          value: '2.0'
                        - field: IssueInstant
                          value: '2024-03-01T12:00:00Z'
                        - field: Destination
                          value: https://idp.example.com/SSO/Redirect
                        - field: Issuer
                          value: https://sp.example.com/metadata
                      xml: >-
                        <?xml version="1.0" encoding="UTF-8"?>

                        <samlp:AuthnRequest
                        xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                        ID="_req_abc123" Version="2.0"
                        IssueInstant="2024-03-01T12:00:00Z"
                        Destination="https://idp.example.com/SSO/Redirect"
                        AssertionConsumerServiceURL="https://sp.example.com/acs">
                          <saml:Issuer>https://sp.example.com/metadata</saml:Issuer>
                          <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
                        </samlp:AuthnRequest>
                    credits_used: 3
                    credits_remaining: null
                failed_status_response_statuscode_not_success:
                  summary: Failed-status Response (StatusCode not Success)
                  value:
                    tool: saml-response-decoder
                    tool_version: 1.0.1
                    outputs:
                      notes:
                        - level: Binding
                          message: HTTP-POST (plain base64, no compression)
                        - level: Warning
                          message: >-
                            SAML status is not Success:
                            urn:oasis:names:tc:SAML:2.0:status:Responder
                        - level: Signature
                          message: No XML signature element found in this document.
                      summary:
                        - field: Document Type
                          value: Response
                        - field: ID
                          value: _fail_1
                        - field: Version
                          value: '2.0'
                        - field: IssueInstant
                          value: '2024-05-01T08:00:00Z'
                        - field: Destination
                          value: https://sp.example.com/acs
                        - field: Issuer
                          value: https://idp.example.com/SSO
                        - field: StatusCode
                          value: urn:oasis:names:tc:SAML:2.0:status:Responder
                        - field: StatusMessage
                          value: Authentication failed
                      xml: >-
                        <samlp:Response
                        xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                        ID="_fail_1" Version="2.0"
                        IssueInstant="2024-05-01T08:00:00Z"
                        Destination="https://sp.example.com/acs">
                          <saml:Issuer>https://idp.example.com/SSO</saml:Issuer>
                          <samlp:Status>
                            <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"/>
                            <samlp:StatusMessage>Authentication failed</samlp:StatusMessage>
                          </samlp:Status>
                        </samlp:Response>
                    credits_used: 3
                    credits_remaining: null
                malformed_input_handled_gracefully:
                  summary: Malformed input (handled gracefully)
                  value:
                    tool: saml-response-decoder
                    tool_version: 1.0.1
                    outputs:
                      notes:
                        - level: Error
                          message: >-
                            The decoded payload is neither XML nor a
                            recognizable DEFLATE/gzip stream.
                      summary: []
                      xml: ''
                    credits_used: 3
                    credits_remaining: null
              schema:
                type: object
                required:
                  - tool
                  - tool_version
                  - outputs
                  - credits_used
                  - credits_remaining
                properties:
                  outputs:
                    type: object
                    properties:
                      notes:
                        type: array
                        items:
                          type: object
                          properties:
                            level:
                              type: string
                              description: Level
                            message:
                              type: string
                              description: Message
                        x-iotools-columns:
                          - level
                          - message
                      summary:
                        type: array
                        items:
                          type: object
                          properties:
                            field:
                              type: string
                              description: Field
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - field
                          - value
                      xml:
                        type: string
                  tool:
                    type: string
                    description: The tool's slug, echoing the {slug} in the request path.
                  tool_version:
                    type: string
                    description: Output-contract version for this tool.
                  credits_used:
                    type: integer
                    description: >-
                      Credits this call consumed, after any settlement refund. 0
                      when metering is disabled.
                  credits_remaining:
                    type:
                      - integer
                      - 'null'
                    description: >-
                      Credits left in the current monthly allowance, or null
                      when metering is disabled.
                  request_id:
                    type: string
                    description: Correlation id, also sent as x-request-id.
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/InsufficientCredits'
        '403':
          $ref: '#/components/responses/ToolNotAllowed'
        '404':
          $ref: '#/components/responses/ToolNotFound'
        '413':
          $ref: '#/components/responses/PayloadTooLarge'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/ToolFailed'
        '503':
          $ref: '#/components/responses/ToolDisabled'
      security:
        - bearerAuth: []
components:
  responses:
    ValidationError:
      description: Invalid request.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/validation_error
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Invalid request
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - validation_error
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              fields:
                type:
                  - object
                  - string
                additionalProperties:
                  type: string
                description: >-
                  What failed: a map of field name → message. Absent when the
                  body itself is malformed; a single string when the failure
                  isn't tied to one field.
          example:
            type: https://iotools.cloud/docs/errors/validation_error
            title: Invalid request
            status: 400
            code: validation_error
            detail: One or more inputs are invalid — see `fields`.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            fields:
              inputString: Required
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/invalid_api_key
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Invalid API key
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - invalid_api_key
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/invalid_api_key
            title: Invalid API key
            status: 401
            code: invalid_api_key
            detail: 'Provide ''Authorization: Bearer <key>''.'
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    InsufficientCredits:
      description: Monthly credit allowance exhausted.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/insufficient_credits
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Insufficient credits
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - insufficient_credits
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              credits_used:
                type: integer
                description: Always 0 — a refused call charges nothing.
              credits_remaining:
                type: integer
                description: Credits left in the allowance — fewer than this call costs.
          example:
            type: https://iotools.cloud/docs/errors/insufficient_credits
            title: Insufficient credits
            status: 402
            code: insufficient_credits
            detail: This call costs 1 credit and 0 remain in this month's allowance.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            credits_used: 0
            credits_remaining: 0
    ToolNotAllowed:
      description: Tool exists but has no API surface.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_not_allowed
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool not available over the API
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_not_allowed
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_not_allowed
            title: Tool not available over the API
            status: 403
            code: tool_not_allowed
            detail: >-
              "Background Remover" is available on iotools.cloud but has no API
              endpoint.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    ToolNotFound:
      description: No such tool.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_not_found
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool not found
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_not_found
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_not_found
            title: Tool not found
            status: 404
            code: tool_not_found
            detail: No tool with that slug. See GET /v1/tools/list.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    PayloadTooLarge:
      description: Body too large.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/payload_too_large
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Payload too large
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - payload_too_large
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/payload_too_large
            title: Payload too large
            status: 413
            code: payload_too_large
            detail: Request body exceeds this tool's size limit.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    RateLimited:
      description: Per-minute rate limit exceeded.
      headers:
        Retry-After:
          description: Seconds to wait before retrying (RFC 9110 delta-seconds).
          schema:
            type: integer
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/rate_limited
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Rate limit exceeded
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - rate_limited
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              retry_after:
                type: integer
                description: >-
                  Seconds until the window resets — the same value as the
                  `Retry-After` header.
          example:
            type: https://iotools.cloud/docs/errors/rate_limited
            title: Rate limit exceeded
            status: 429
            code: rate_limited
            detail: Too many requests. Retry in 30s.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            retry_after: 30
    ToolFailed:
      description: Tool failed to run.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/processing_error
                  - https://iotools.cloud/docs/errors/internal_error
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool failed to run
                  - Internal error
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - processing_error
                  - internal_error
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              credits_used:
                type: integer
                description: >-
                  Always 0 on `processing_error` — a failed run is refunded,
                  floor included.
              credits_remaining:
                type: integer
                description: >-
                  Credits left after the refund. Absent when metering is
                  disabled.
          example:
            type: https://iotools.cloud/docs/errors/processing_error
            title: Tool failed to run
            status: 500
            code: processing_error
            detail: The tool failed to run. Please try again.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            credits_used: 0
    ToolDisabled:
      description: Tool temporarily disabled.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_disabled
                  - https://iotools.cloud/docs/errors/api_unconfigured
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool temporarily disabled
                  - API not configured
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_disabled
                  - api_unconfigured
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_disabled
            title: Tool temporarily disabled
            status: 503
            code: tool_disabled
            detail: This tool is temporarily unavailable. Try again shortly.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: iot_live_…

````