Configuring Integration Server, Mediator, and Virtual Services for Bearer Tokens
The request must contain a valid SAML Bearer token (instead of a Holder-of-Key token).
The request's SOAP body
does not have to be signed by the client using the private key corresponding to the public key present in the SAML assertion.