SAML: Invalid SAML response — signature validation failed / audience mismatch / response expired (NotOnOrAfter)
The service provider rejected the IdP’s SAML assertion — wrong certificate, Audience/Entity ID mismatch, ACS URL mismatch, or clock skew.
Seen on:
REST API
Meaning
SAML is unforgiving: the SP must trust the IdP’s current signing certificate, the Audience must equal the SP Entity ID, the Destination/ACS URL must match, and NotBefore/NotOnOrAfter require synced clocks.
Common causes
- IdP signing certificate rotated (SP has the old one)
- Entity ID / Audience mismatch
- ACS URL or Destination mismatch (http vs https, trailing slash)
- Clock skew making the assertion expired/not yet valid
⚡ Quick fix
- Re-import IdP metadata (certificate) on the SP
- Make Entity ID and ACS URL identical on both sides
- Sync clocks; allow small skew
Detailed fix by platform
Shell
- bash
# decode a SAMLResponse captured from the browser echo "$SAML_RESPONSE" | base64 -d | xmllint --format - | grep -E 'Audience|Destination|NotOnOrAfter|X509Certificate' | head
How to diagnose
- Assertion — Audience, Destination, times
- Certificate — Matches metadata?
- Clocks — In sync?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS50020 AADSTS50020: User account from identity provider does not exist in tenant and cannot access the application
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- Clock skew too great Kerberos: Clock skew too great (KRB_AP_ERR_SKEW)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026