Enterprise federation
Assertions, metadata, certificates, ACS URLs and NameID mapping.
Open field guide →Practical diagnostics for SAML, OAuth 2.0 and OpenID Connect. Find the failure, understand the cause and get your users back in.
23:41:06 SSO request received
23:41:06 Protocol OpenID Connect
23:41:07 Authorization code ✓ valid
23:41:07 Token signature ✓ verified
23:41:07 Audience claim ✕ mismatch
Token audience does not match this client ID.
Compare the aud claim with your configured client identifier.
Choose the symptom closest to your issue. We’ll point you toward the most likely checks—without asking for secrets.
Never paste passwords, active access tokens, refresh tokens, session cookies or private signing keys. Redact personal data before sharing logs.
Each protocol fails differently. Start with the moving parts that matter.
Assertions, metadata, certificates, ACS URLs and NameID mapping.
Open field guide →Authorization codes, PKCE, scopes, redirect URIs and consent.
Open field guide →ID tokens, discovery, nonce, claims, JWKS and userinfo.
Open field guide →Most authentication incidents can be narrowed down with five calm, repeatable checks.
One user, one tenant, one application—or everyone?
Look for clock drift, certificate rotation and deployments.
Issuer, audience, entity ID, client ID and redirect URI.
Error codes, request IDs and timestamps—not secrets.
Change one variable, record it, verify and roll back if needed.
Start with the symptom and work toward evidence—one safe check at a time.
Start diagnosis →