Your app runs smoothly on Tomcat until the security team asks for single sign-on. Suddenly, you are in acronym city: SAML, SP, IdP, metadata, assertions, bindings. It feels like you traded uptime for paperwork. Yet a clean SAML Tomcat setup can be simple if you understand what actually happens under