🎉 Beta is now open

Book a free demo
Skip to main content

Troubleshooting SSO sign-in

What to do when SSO isn't working as expected.

Updated

"Invalid SAML response"

Usually a clock-skew problem. Make sure both your IdP server and any reverse proxies have NTP enabled.

"User not found"

Your IdP isn't sending the email in the expected attribute. Confirm NameID is set to EmailAddress format.

"AudienceRestriction mismatch"

The Audience URI in your IdP doesn't match our Entity ID. Re-copy the Entity ID from Settings → SSO and paste it into your IdP exactly.

"Signature validation failed"

Your IdP's signing certificate has rotated. Open the IdP, copy the new certificate, paste it into the HelloCivic SSO settings.

SSO works for Owner but not Members

Check that your IdP has actually assigned the app to those members. Most "missing user" errors trace back to an unassigned account in the IdP.

Still stuck?

Submit a support ticket with the SAML response (you can grab it via the SAML-tracer browser extension). We'll usually spot the problem in minutes.

Was this article helpful?

Your feedback helps us improve our docs.