It’s really easy, I promise.
To put it in layman’s terms, it’s a Single Sign On flow that is initiated by the Identity Provider sending an unsolicited SAML response to the Service Provider.
For more clarification, here is a picture thats worth a thousand words:
It’s really as simple as it seems. However there are a few security measures that are put in place to validate who the identity provider is.
idp_public_keywith the SP