FREE CHECKER
What’s hiding in your SSO metadata?
Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.
SAMPLEA bundled document, scanned as if today were 6 September 2026. Your own URL goes in the box above.
All signing certificates have expired.
What we found
All signing certificates have expired
The most recent one expired on 2026-08-01, 36 days ago. Single sign-on for this connection is down now.
Certificates
| Subject | Use | Status | Valid from | Valid until | SHA-256 |
|---|---|---|---|---|---|
| Legacy SigningRSA 2048-bit | signing | Expired | 2024-01-01 | 2026-08-0136d ago | 1C:17:FE:D0… |
Document detailsshowhide
Entity ID
https://legacy.example.com/idp
Endpoints
- SingleSignOnService · HTTP-Redirect
https://legacy.example.com/sso
- SingleSignOnService · HTTP-POST
https://legacy.example.com/sso
NameID formats
- urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
- urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Content hash
12bc2bda525f2e5f05b78146031d9cf51484813c2d4d899de72cc7e1e7c24204
A fingerprint of the fields we watch. Monitoring compares this between scans, so reformatting the document does not raise an alert but a changed certificate or endpoint does.
Handle this one. Get ahead of the next.
Use the findings above to plan your next step. Join the monitoring waitlist for advance alerts and a clear report to share with your customer’s IT admin.