Skip to content
notafter.SSO error reference

FREE CHECKER

What’s hiding in your SSO metadata?

Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.

No public URL? Paste the document instead
Public documents only Nothing storedNo URL handy? See a sample:Entra ID mid-rolloverExpired certificateHealthy Okta connection

Certificate windows

Both notBefore and notAfter, because a certificate that is not valid yet fails logins exactly like an expired one.

Rollover awareness

When your IdP has already published the replacement, we say so instead of raising a false alarm.

Readable failures

If the URL returns a login page or a 403, you get told which, not a generic error.