Skip to content
notafter.
FOR B2B SAAS TEAMS RUNNING THEIR OWN SSO

SSO without
the unpleasant surprises.

An expired certificate shouldn’t take your customers offline. Check your SSO today. Join the waitlist for monitoring and reports your customer’s IT admin can act on.

No sign-up No IdP credentials Just your metadata
app.notafter.dev / overviewPRODUCT PREVIEW
SSO overview

Every connection. One less thing to worry about.

Connections
24
Healthy
22
Need attention
02
Your connections Last scan 4 minutes ago
ConnectionIdentity providerCertificate expiresStatus
A
Acme · Production
acme.com
Microsoft Entra ID23 days
Expiring soon
L
Linear · Workforce
linear.app
Okta184 days
Healthy
R
Ramp · Enterprise
ramp.com
Microsoft Entra ID246 days
Healthy
V
Vercel · Internal
vercel.com
Google Workspace312 days
Healthy
Showing 4 of 24 connectionsExplore monitoring

Monitoring is coming soon · Illustrative dashboard with sample data

Built around the identity providers you already use

Microsoft Entra IDokta.Google WorkspacepingidentityAD FS

COMING SOON · CONTINUOUS MONITORING

The quiet layer between
you and an SSO outage.

Certificates expire. Metadata changes.
Your team deserves to hear about it before your customers do.

A CLEAR NEXT STEP FOR YOUR CUSTOMER

More useful than “your cert expires.”

A report Customer Success can send straight to the customer’s IT admin: the affected connection, certificate dates and a practical rotation checklist. No authentication platform migration.

Planned: 13 months of change history to support security questionnaires. A record of what changed, built over time.

Acme · SSO connection report23 days left

For your identity administrator · Sample report

  1. 1. Review the signing certificate expiring September 29.
  2. 2. Publish its replacement and confirm the validity window.
  3. 3. Update the service provider’s trusted certificate and verify sign-in.

Report sharing and history are planned, not available yet.

Expiry dates. On your radar.

Get a heads-up at 90, 30, 7 and 1 day before a certificate expires. Make rotation a routine task, not an emergency.

Acme · Signing certificate23 days left
TODAY
90d30d7d1dEXPIRY
One alert per threshold. No daily noise.

Know what changed. And when.

Spot new signing certificates, key rotations and endpoint changes. Get a readable diff instead of a wall of XML.

Metadata change detected09:41 AM
signing_certificates
+ certificate: 8F:21:BE:04:…
valid_from: 2026-10-01
valid_until: 2027-10-01
New certificate added. Likely an upcoming rotation.

The right channel. The right time.

Send alerts to email, Slack or your own webhook. Keep the people who can act in the loop.

A report you can hand over.

Share a connection report with your customer’s IT admin, complete with dates and next steps.

Watch the watcher, too.

See when each connection was last scanned. Unreachable metadata never passes as healthy.

HOW PLANNED MONITORING WILL WORK

From metadata to peace of mind.

No agents to install. No admin access to negotiate.

01

Add your metadata.

Paste a public SAML metadata or OIDC discovery URL. Give the connection a name you’ll recognize.

02

We keep an eye on it.

Daily scans track certificate validity and meaningful metadata changes across your connections.

03

Act before it’s urgent.

Get a clear alert with time to respond. Share the report, plan the rotation and get back to your day.

VISIBILITY WITHOUT PRIVILEGE

Your metadata.
Never your credentials.

You shouldn’t have to hand over the keys to check the locks. NotAfter reads public identity provider metadata. We don’t need access to your IdP. Or your customers’.

No tenant admin consent

No passwords, tokens or client secrets

Read-only by design

THE ACCESS WE NEED

Public metadata URL

https://idp.example.com/metadata.xml

Admin credentialsNot needed
Directory accessNot needed
Client secretsNot needed
Less access. A smaller trust boundary.

MEET YOUR NEXT SANITY CHECK

What’s hiding in
your SSO metadata?

One check. Every signing certificate, its validity window and how long you actually have left. No account, no credentials, nothing stored.

We read only what your customers can read

SSO certificate checker

FREE
No public URL? Paste the document instead

A FEW GOOD QUESTIONS

The details matter.

What exactly does NotAfter monitor?

The planned monitoring service checks SAML signing certificate validity and changes to identity provider metadata every day. For OIDC, it tracks key IDs and discovery endpoints. Certificate expiry is available only when a JWK includes an x5c certificate chain.

Do I need to give you access to my identity provider?

No. NotAfter is designed to read publicly accessible SAML metadata and OIDC discovery documents. It does not require administrator consent, passwords or access to your directory.

Can you detect when an OIDC client secret expires?

Client secret expiry dates are not public. Planned monitoring will let you enter an expiry date yourself for a scheduled reminder. NotAfter does not automatically discover client secret expirations or ask you to share the secret itself.

Will I get an alert every day?

The design uses separate alerts at 90, 30, 7 and 1 day before expiry, plus expired and not-yet-valid states. Each threshold is notified once. Meaningful metadata changes generate their own alerts.

Can I try it today?

The free checker is live and reads real metadata: paste a public SAML metadata or OpenID discovery URL and you get every certificate with its dates. Scheduled monitoring, alert delivery and the per-connection report are still being built — that is what the waitlist is for. Pricing will be published when monitoring opens.

What do you store when I use the checker?

The document is fetched, parsed in memory and rendered. It is not written to a database and not kept. We only fetch http and https URLs on ports 80 and 443, and we refuse any address that resolves inside a private network.

Want this watched for you?

Monitoring is being built now: daily scans of every connection, alerts at 90, 30, 7 and 1 day, and a report you can hand to your customer’s IT admin. Leave an address and you will hear when it opens.

One email when it opens. Nothing else, and no sharing.

YOUR NEXT INCIDENT? LET’S SKIP IT.

A little ahead.
A lot more at ease.

Keep your customers signing in.
Keep certificate surprises out of your day.