SAML can.
In general, SAML is complicated because (1) auth is complicated (2) XML is complicated (3) canonicalization/signatures are complicated.
Some of those are unforced errors, some are historical facts.
Why not? The flow can be entirely client side. OpenID discovery and PAR is optional and those would require direct connections
reply
SAML does not require JavaScript to do that.
SAML can.
In general, SAML is complicated because (1) auth is complicated (2) XML is complicated (3) canonicalization/signatures are complicated.
Some of those are unforced errors, some are historical facts.