I need to use SAML assertion lifetime for deciding the expiry of the API key, is there any way we can get the SAML session/assertion validity from the identity provider, I know