Skip to main content

How do I troubleshoot SSO errors?

Where to look depends on whether you're using the current SSO setup or the legacy SAML-only setup.

If you see one SSO configuration option

A single SSO option on the Authentication page indicates you are using the latest version of our SSO.

The setup guidance for the current SSO flow — provider-specific steps, screenshots, and connection testing — is accessible inside the setup portal itself. If something isn't working, the portal's live connection test will tell you what's failing before you finish.

If you've completed setup and are running into a login issue, contact Rebrandly Support in the chatbot below with:

  • Which identity provider you're using.

  • The exact error message or a screenshot.

  • Whether the error happens before or after you're redirected back to Rebrandly.

If you see two configuration options

Two SSO options indicates you're using the older, legacy SSO connection.

These are the most common errors we see when setting up the legacy SSO.

Symptom

Likely cause

Fix

"Domain not recognized" at login

Email domain not added, or typo in the domain

Re-check the SSO settings in Rebrandly. The domain must exactly match the email suffix.

Redirect loops back to IdP

ACS URL in IdP doesn't match Rebrandly's

Re-copy the ACS URL from Rebrandly SSO settings into the IdP

Login completes at IdP but lands on a Rebrandly error page

Missing or incorrect SAML claims

Verify both name and emailaddress claims are being sent

Nothing happens after IdP login

NameID not persistent, or format mismatch

Set NameID format to persistent/email address

Invited user never receives the invite

Pre-existing free Rebrandly account using the same email

Contact Rebrandly Support to remove the conflicting account before re-inviting

"It used to work, now it doesn't"

IdP certificate rotation on your side

Confirm your IdP certificate hasn't expired or rotated. Re-publish metadata if needed.

If your issue isn't listed, contact Rebrandly Support in the chatbot below with:

  • Which IdP you're using.

  • The exact error message or screenshot.

  • If possible, a SAML tracer extension to capture SAML request/responses.

Did this answer your question?