Okta SSL certificate status

Valid — 73 days until expiry(okta.com)

This page shows the Okta SSL certificate as served by okta.com, read from a live TLS handshake by an independent CertPost probe and rechecked hourly: expiry, issuer, hostname coverage, the full chain, and the negotiated protocol.

Last checked 2026-09-20 07:46 UTC. CertPost is not affiliated with Okta.

Certificate details

Subjectokta.com
IssuerAmazon RSA 2048 M01
Valid from2025-11-03
Expires2026-12-02
Days remaining73
Chain validyes
Hostname matchyes
Negotiated protocolTLSv1.3
TLS versions acceptedTLSv1, TLSv1.1, TLSv1.2, TLSv1.3

Hostnames this certificate covers

okta.com, okta-emea.com, www.okta.com

Certificate chain as served

okta.comissued by Amazon RSA 2048 M01 · expires 2026-12-02
Amazon RSA 2048 M01issued by Amazon Root CA 1 · expires 2030-08-23
Amazon Root CA 1issued by Starfield Services Root Certificate Authority - G2 · expires 2037-12-31
Starfield Services Root Certificate Authority - G2self-signed (root) · expires 2037-12-31

Common questions

Is the Okta SSL certificate expired?

At the last check, the certificate okta.com serves was within its validity period. It expires on 2026-12-02, 73 days from that check.

When does the Okta SSL certificate expire?

The certificate okta.com is currently serving expires on 2026-12-02 (73 days from the last check). Large services rotate certificates long before that date.

Who issued the Okta SSL certificate?

The certificate was issued by Amazon RSA 2048 M01.

How is this checked?

A CertPost probe opens a real TLS connection to okta.com on port 443 and reads the certificate the server presents, the same way a browser does. The result is cached and refreshed hourly.

Okta rotates certificates without downtime. Your own domains are the ones that expire quietly — watch 3 free, no card.

Monitor your certificates

Or run a one-off check with the free SSL checker.

One check now, or every day from now on.

3 certificates free forever · No agent · No credit card