FREE CHECKER
What’s hiding in your SSO metadata?
Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.
SAMPLEA bundled document, scanned as if today were 6 September 2026. Your own URL goes in the box above.
2 valid signing certificates. Nothing expires for another 184 days.
Certificates
| Subject | Use | Status | Valid from | Valid until | SHA-256 |
|---|---|---|---|---|---|
| Example IdP SigningRSA 2048-bit | signing | Valid | 2026-01-01 | 2027-03-09184d left | F3:70:CA:CD… |
| Example IdP Signing AltRSA 2048-bit | signing | Valid | 2026-01-01 | 2027-06-01268d left | FE:C7:20:98… |
Document detailsshowhide
Entity ID
http://www.okta.com/exk1a2b3c4d5e6f7g8h9
Endpoints
- SingleSignOnService · HTTP-Redirect
https://example.okta.com/app/example_app_1/exk1a2b3c4d5e6f7g8h9/sso/saml
- SingleSignOnService · HTTP-POST
https://example.okta.com/app/example_app_1/exk1a2b3c4d5e6f7g8h9/sso/saml
NameID formats
- urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
- urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Content hash
27520f0e67336b9aaf73548c397225e09b9611eb3e199c2ae2494e9355a1dc86
A fingerprint of the fields we watch. Monitoring compares this between scans, so reformatting the document does not raise an alert but a changed certificate or endpoint does.
One connection checked. How many more?
This connection looks healthy today. Join the waitlist for a daily view of all your customer connections and reports your team can hand over.