If the SAML Response was sent after an Authn Request, the Request ID can also be provided in order to validate it too.

Typically, a parser can be set to be validating or non-validating at runtime.without validating signature, expiration and audience. It allows you to get information from the token like the Issuer name in order to obtain the right public key to validate the token in a multi-providers scenario.