Skip to content
notafter.SSO error reference

FREE CHECKER

What’s hiding in your SSO metadata?

Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.

No public URL? Paste the document instead
Public documents only Nothing storedNo URL handy? See a sample:Entra ID mid-rolloverExpired certificateHealthy Okta connection

SAMPLEA bundled document, scanned as if today were 6 September 2026. Your own URL goes in the box above.

Action needed nowUnrecognised providerSAML metadata

All signing certificates have expired.

What we found

  • All signing certificates have expired

    The most recent one expired on 2026-08-01, 36 days ago. Single sign-on for this connection is down now.

Certificates

SubjectUseStatusValid fromValid untilSHA-256
Legacy SigningRSA 2048-bitsigningExpired2024-01-012026-08-0136d ago1C:17:FE:D0…
Document detailsshow

Entity ID

https://legacy.example.com/idp

Endpoints

  • SingleSignOnService · HTTP-Redirect

    https://legacy.example.com/sso

  • SingleSignOnService · HTTP-POST

    https://legacy.example.com/sso

NameID formats

  • urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
  • urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Content hash

12bc2bda525f2e5f05b78146031d9cf51484813c2d4d899de72cc7e1e7c24204

A fingerprint of the fields we watch. Monitoring compares this between scans, so reformatting the document does not raise an alert but a changed certificate or endpoint does.

Handle this one. Get ahead of the next.

Use the findings above to plan your next step. Join the monitoring waitlist for advance alerts and a clear report to share with your customer’s IT admin.

One email when it opens. Nothing else, and no sharing.