> Thanks, Scott. By "generally", are there caveots for IDP logout with session > cookies that I need to be aware of? The edge case is if you deliver a SAML logout request that identifies the session but don't deliver the cookie. I don't believe I implemented anything yet to peg the NameID for later disposal, so that's a hole and I think it will fail the request. -- Scott