Skip to content
notafter.SSO error reference

FREE CHECKER

What’s hiding in your SSO metadata?

Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.

No public URL? Paste the document instead
Public documents only Nothing storedNo URL handy? See a sample:Entra ID mid-rolloverExpired certificateHealthy Okta connection

SAMPLEA bundled document, scanned as if today were 6 September 2026. Your own URL goes in the box above.

HealthyOktaSAML metadata

2 valid signing certificates. Nothing expires for another 184 days.

Certificates

SubjectUseStatusValid fromValid untilSHA-256
Example IdP SigningRSA 2048-bitsigningValid2026-01-012027-03-09184d leftF3:70:CA:CD…
Example IdP Signing AltRSA 2048-bitsigningValid2026-01-012027-06-01268d leftFE:C7:20:98…
Document detailsshow

Entity ID

http://www.okta.com/exk1a2b3c4d5e6f7g8h9

Endpoints

  • SingleSignOnService · HTTP-Redirect

    https://example.okta.com/app/example_app_1/exk1a2b3c4d5e6f7g8h9/sso/saml

  • SingleSignOnService · HTTP-POST

    https://example.okta.com/app/example_app_1/exk1a2b3c4d5e6f7g8h9/sso/saml

NameID formats

  • urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
  • urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Content hash

27520f0e67336b9aaf73548c397225e09b9611eb3e199c2ae2494e9355a1dc86

A fingerprint of the fields we watch. Monitoring compares this between scans, so reformatting the document does not raise an alert but a changed certificate or endpoint does.

One connection checked. How many more?

This connection looks healthy today. Join the waitlist for a daily view of all your customer connections and reports your team can hand over.

One email when it opens. Nothing else, and no sharing.