SAML response invalid 🔐 Authentication

SAML: Invalid SAML response — signature validation failed / audience mismatch / response expired (NotOnOrAfter)

The service provider rejected the IdP’s SAML assertion — wrong certificate, Audience/Entity ID mismatch, ACS URL mismatch, or clock skew.

Seen on: REST API

Meaning

SAML is unforgiving: the SP must trust the IdP’s current signing certificate, the Audience must equal the SP Entity ID, the Destination/ACS URL must match, and NotBefore/NotOnOrAfter require synced clocks.

Common causes

  • IdP signing certificate rotated (SP has the old one)
  • Entity ID / Audience mismatch
  • ACS URL or Destination mismatch (http vs https, trailing slash)
  • Clock skew making the assertion expired/not yet valid

⚡ Quick fix

  1. Re-import IdP metadata (certificate) on the SP
  2. Make Entity ID and ACS URL identical on both sides
  3. Sync clocks; allow small skew

Detailed fix by platform

Shell

  1. bash
    # decode a SAMLResponse captured from the browser
    echo "$SAML_RESPONSE" | base64 -d | xmllint --format - | grep -E 'Audience|Destination|NotOnOrAfter|X509Certificate' | head

How to diagnose

  1. Assertion — Audience, Destination, times
  2. Certificate — Matches metadata?
  3. Clocks — In sync?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.