Adding to this thread:I found out that there is another scenario in which the SAMLAuthenticationHandler returns a 204. If you're passing the origin Passing the Origin header to the author (via the dispatcher’s /clientheaders setting), this causes the /saml_login endpoint to return a 204 No Content ...