FREE CHECKER
What’s hiding in your SSO metadata?
Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.
Public documents only Nothing stored·No URL handy? See a sample:Entra ID mid-rolloverExpired certificateHealthy Okta connection
Certificate windows
Both notBefore and notAfter, because a certificate that is not valid yet fails logins exactly like an expired one.
Rollover awareness
When your IdP has already published the replacement, we say so instead of raising a false alarm.
Readable failures
If the URL returns a login page or a 403, you get told which, not a generic error.