Skip to content
notafter.SSO error reference

FREE CHECKER

What’s hiding in your SSO metadata?

Paste a public SAML metadata or OpenID discovery URL. We read it, decode every certificate and tell you exactly how long you have. Nothing is stored and no credentials are ever involved.

No public URL? Paste the document instead
Public documents only Nothing storedNo URL handy? See a sample:Entra ID mid-rolloverExpired certificateHealthy Okta connection

SAMPLEA bundled document, scanned as if today were 6 September 2026. Your own URL goes in the box above.

Worth knowingMicrosoft Entra IDSAML metadata

1 valid signing certificate. The earliest expiry is 2026-09-29, in 23 days.

What we found

  • A replacement certificate is already published

    Acme SSO Signing 2027 becomes valid on 2026-09-15 and runs until 2027-09-15. The rotation is prepared, so the approaching expiry below is expected rather than urgent.

  • Acme SSO Signing expires in 23 days

    Valid until 2026-09-29. A successor certificate is already in the metadata, so this is a rotation in progress.

Certificates

SubjectUseStatusValid fromValid untilSHA-256
Acme SSO SigningRSA 2048-bitsigningValid2025-09-292026-09-2923d left45:6E:F9:75…
Acme SSO Signing 2027RSA 2048-bitsigningNot yet valid2026-09-152027-09-15starts in 9d34:05:0C:8E…
Document detailsshow

Entity ID

https://sts.windows.net/c0ffee00-1234-5678-9abc-def012345678/

Endpoints

  • SingleSignOnService · HTTP-Redirect

    https://login.microsoftonline.com/c0ffee00-1234-5678-9abc-def012345678/saml2

  • SingleSignOnService · HTTP-POST

    https://login.microsoftonline.com/c0ffee00-1234-5678-9abc-def012345678/saml2

NameID formats

  • urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
  • urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Content hash

81576b776c60e2b6ef054012b3f0d6847e557156010b072fc1f495949789dff7

A fingerprint of the fields we watch. Monitoring compares this between scans, so reformatting the document does not raise an alert but a changed certificate or endpoint does.

Want this watched for you?

Monitoring is being built now: daily scans of every connection, alerts at 90, 30, 7 and 1 day, and a report you can hand to your customer’s IT admin. Leave an address and you will hear when it opens.

One email when it opens. Nothing else, and no sharing.