Skip to main content

How do I troubleshoot SSO errors?

Updated today

These are the most common errors we see when setting up SSO.

Symptom

Likely cause

Fix

"Domain not recognized" at login

Email domain not added, or typo in the domain

Re-check the SSO settings in Rebrandly. The domain must exactly match the email suffix.

Redirect loops back to IdP

ACS URL in IdP doesn't match Rebrandly's

Re-copy the ACS URL from Rebrandly SSO settings into the IdP

Login completes at IdP but lands on a Rebrandly error page

Missing or incorrect SAML claims

Verify both name and emailaddress claims are being sent

Nothing happens after IdP login

NameID not persistent, or format mismatch

Set NameID format to persistent/email address

Invited user never receives the invite

Pre-existing free Rebrandly account using the same email

Contact Rebrandly Support to remove the conflicting account before re-inviting

"It used to work, now it doesn't"

IdP certificate rotation on your side

Confirm your IdP certificate hasn't expired or rotated. Re-publish metadata if needed.

If the issue isn't listed, contact Rebrandly Support in the chatbot below with:

  • Which IdP you're using.

  • The exact error message or screenshot.

  • If possible, a SAML tracer extension to capture SAML request/responses.

Did this answer your question?