Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SSOJet SSO Config Validator

Marketplace Test License: MIT

A zero-config GitHub Action that validates SAML 2.0 metadata and OpenID Connect discovery documents in CI, so broken SSO configuration is caught in a pull request instead of by your customers.

Built and maintained by SSOJet — the SSO & SCIM platform that lets B2B SaaS teams ship enterprise login in days, not quarters.

Why this exists

Most SSO outages are not code bugs — they are configuration drift: a signing certificate that quietly expired, an ACS URL that slipped back to http://, a discovery document missing jwks_uri. These never show up in unit tests because the config lives outside your application code. This Action treats that config like any other artifact: it gets checked on every push.

For a deeper walkthrough of SAML and OIDC setup, see the SSOJet documentation and the SSOJet blog.

Usage

- name: Validate SSO configuration
  uses: ssojet/sso-config-validator@v1
  with:
    saml-metadata: config/saml/idp-metadata.xml
    oidc-discovery: https://auth.example.com/.well-known/openid-configuration

Either input is optional — supply one or both. Paths are resolved from the repo checkout; values starting with http(s):// are fetched live.

Inputs

Input Default Description
saml-metadata '' Path or URL to a SAML 2.0 metadata XML document.
oidc-discovery '' Path or URL to an OIDC discovery document.
expected-issuer '' Expected OIDC issuer / SAML entityID. Fails on mismatch.
check-cert-expiry true Validate the SAML signing certificate's expiry window.
cert-expiry-threshold-days 30 Warn when a certificate expires within this many days.
fail-on error Minimum severity that fails the build: error, warning, or never.

Outputs

Output Description
result pass or fail.
errors Number of errors found.
warnings Number of warnings found.

What gets checked

SAML metadata

  • Well-formed XML with a valid EntityDescriptor / EntitiesDescriptor root
  • Present and matching entityID
  • A usable IDPSSODescriptor or SPSSODescriptor
  • A signing certificate that parses and has not expired (with an early-warning window)
  • SSO/ACS endpoints with recognized bindings and HTTPS locations

OIDC discovery

  • Valid JSON with all spec-required members (issuer, authorization_endpoint, token_endpoint, jwks_uri, response_types_supported, subject_types_supported, id_token_signing_alg_values_supported)
  • HTTPS issuer with no query/fragment, and HTTPS endpoints throughout
  • Recommended members and algorithm support (RS256, Authorization Code flow)

Example: warn early on expiring certificates

- uses: ssojet/sso-config-validator@v1
  with:
    saml-metadata: config/idp-metadata.xml
    cert-expiry-threshold-days: 45
    fail-on: warning

Tired of maintaining SSO config by hand?

This Action helps you catch problems. SSOJet helps you avoid them — a single API and pre-built UI for SAML, OIDC, and SCIM directory sync across every major identity provider. Start for free.

License

MIT © SSOJet

About

Validate SAML metadata and OIDC discovery documents in CI — catch SSO misconfigurations before they reach production.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages