Free SAML Metadata Validator: Certificates, Endpoints and Expiry
Paste or upload SAML metadata XML to check the entity ID, IdP and SP endpoints, bindings, NameID formats, certificate expiry and key size, validUntil and signature.
Issues
Document
Signatures are reported, not cryptographically verified.
Everything you already do here stays free, with the same limits.
The XML is read in your browser and never uploaded. Files with a DTD or entity declarations are refused, the same safety rule our API uses.
What this tool does
Paste SAML 2.0 metadata or drop the XML file, and the validator shows what is inside and what is wrong with it: the entity ID, the IdP and SP roles, every endpoint with its binding, the NameID formats, and each signing and encryption certificate with its expiry date and key size.
Every problem is listed with a severity. A certificate that has expired, an endpoint on plain HTTP or a missing single sign-on service is high; a certificate that expires within 45 days, a SHA-1 signature or a metadata file that expires within a week is medium. The score starts at 100 and loses 15 points for each high issue, 7 for each medium and 3 for each low.
How to use it
- Get the metadata from your identity provider or app. It is usually a download link or a URL ending in metadata or FederationMetadata.xml.
- Paste the XML into the box, or choose or drop the file.
- Press Validate metadata.
- Read Issues first, then check the certificates: the end date, the days left and the key size.
What to check before a certificate expires
- Publish the new certificate in the metadata next to the old one, as a second signing key.
- Let every partner refresh the metadata. Many do it daily; some only when someone uploads it by hand.
- Switch signing to the new key, wait, and only then remove the old certificate.
Free, Pro and Pro+
| Free | Pro | Pro+ | |
|---|---|---|---|
| Metadata files per check | 1 | 50 | 50 |
| CSV export of every certificate and issue | — | Yes | Yes |
| Result quality | The same on every plan | ||
| Server tools paid with credits | With a credit pack | With a credit pack | 300 credits every month |
Pro+ credits pay for server tools: fast speech to text and fast auto subtitles. A credit pack (150 credits, valid for 12 months) works on any plan. Compare plans.
Frequently asked questions
What does this SAML metadata validator check?
The entity ID, whether the file describes an identity provider (IdP), a service provider (SP) or both, every single sign-on, assertion consumer, logout and artifact endpoint with its binding, the NameID formats, every certificate (expiry date, days left, key type and size, signature hash, self-signed or not, SHA-256 fingerprint), the validUntil date and whether the document is signed. Problems are listed as high, medium, low or info, and they add up to a score out of 100.
Is my metadata uploaded anywhere?
No. The XML is read by your browser on your own device and is not sent to us or anyone else.
Does it verify the XML signature?
No. It reports whether the metadata is signed and with which algorithm, and flags SHA-1, but it does not check the signature against a key. Verifying needs the federation's trusted key, which this page does not have.
Why is a file with a DOCTYPE rejected?
SAML metadata never needs a DTD or entity declarations, and they are how XML files are used to attack parsers. The validator refuses them, the same rule our API uses.
When does a certificate count as expiring?
Within 45 days of its end date. That gives you time to publish the new certificate next to the old one, let partners pick up the metadata and then remove the old one.
Is the result the same as your API?
Yes. The checks, severities, points and wording match the SAML metadata check of the SSO Config Doctor API. The API can also fetch metadata from a URL and check OpenID Connect providers, which a web page cannot do for any site because browsers block those requests unless the provider allows them.