A zero-config GitHub Action that validates SAML 2.0 metadata and OpenID Connect discovery documents in CI, so broken SSO configuration is caught in a pull request instead of by your customers.
Built and maintained by SSOJet — the SSO & SCIM platform that lets B2B SaaS teams ship enterprise login in days, not quarters.
Most SSO outages are not code bugs — they are configuration drift: a signing certificate that quietly expired, an ACS URL that slipped back to http://, a discovery document missing jwks_uri. These never show up in unit tests because the config lives outside your application code. This Action treats that config like any other artifact: it gets checked on every push.
For a deeper walkthrough of SAML and OIDC setup, see the SSOJet documentation and the SSOJet blog.
- name: Validate SSO configuration
uses: ssojet/sso-config-validator@v1
with:
saml-metadata: config/saml/idp-metadata.xml
oidc-discovery: https://auth.example.com/.well-known/openid-configurationEither input is optional — supply one or both. Paths are resolved from the repo checkout; values starting with http(s):// are fetched live.
| Input | Default | Description |
|---|---|---|
saml-metadata |
'' |
Path or URL to a SAML 2.0 metadata XML document. |
oidc-discovery |
'' |
Path or URL to an OIDC discovery document. |
expected-issuer |
'' |
Expected OIDC issuer / SAML entityID. Fails on mismatch. |
check-cert-expiry |
true |
Validate the SAML signing certificate's expiry window. |
cert-expiry-threshold-days |
30 |
Warn when a certificate expires within this many days. |
fail-on |
error |
Minimum severity that fails the build: error, warning, or never. |
| Output | Description |
|---|---|
result |
pass or fail. |
errors |
Number of errors found. |
warnings |
Number of warnings found. |
SAML metadata
- Well-formed XML with a valid
EntityDescriptor/EntitiesDescriptorroot - Present and matching
entityID - A usable
IDPSSODescriptororSPSSODescriptor - A signing certificate that parses and has not expired (with an early-warning window)
- SSO/ACS endpoints with recognized bindings and HTTPS locations
OIDC discovery
- Valid JSON with all spec-required members (
issuer,authorization_endpoint,token_endpoint,jwks_uri,response_types_supported,subject_types_supported,id_token_signing_alg_values_supported) - HTTPS issuer with no query/fragment, and HTTPS endpoints throughout
- Recommended members and algorithm support (
RS256, Authorization Code flow)
- uses: ssojet/sso-config-validator@v1
with:
saml-metadata: config/idp-metadata.xml
cert-expiry-threshold-days: 45
fail-on: warningThis Action helps you catch problems. SSOJet helps you avoid them — a single API and pre-built UI for SAML, OIDC, and SCIM directory sync across every major identity provider. Start for free.
MIT © SSOJet