SSO
Troubleshooting SAML SSO
Sign-in failures, certificate errors, settings you can’t reach, and people who can’t join.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Sign-in failures, certificate errors, settings you can’t reach, and people who can’t join.
| Symptom | Cause and fix |
|---|---|
| The SAML settings show an upgrade prompt, but you’re on Enterprise | No domain is registered yet. The SAML settings unlock once Blinq adds at least one domain to your workspace. Email support@blinq.me with the domains you want covered. |
| Sign-in fails with a signature or invalid document error | The identity provider isn’t signing the response. In Entra ID, set Signing Option to Sign SAML response and assertion under SAML Certificates. Entra has been known to reset this, so re-check it if sign-in breaks after working. |
| Sign-in fails after working for months | Check the signing option above, and confirm the Blinq application still exists in your identity provider — removing it breaks sign-in for everyone on your domains. |
| Sign-in returns a 404 | The identity provider values are in the wrong Blinq fields. The sign-on URL goes in Single Sign-On URL and the issuer or identifier goes in Identity Provider Entity ID — it’s easy to swap these two. |
| Launching Blinq from the app tile returns a server error | Starting from the identity provider requires enforcement to be switched on as well. Contact support before enabling it, and see How SAML SSO works. |
| Someone still sees password and email code options | Enforcement isn’t switched on, or their address isn’t on a registered domain. Enforcement is matched on the email domain someone signs in with. |
| A team member is told their account is already in use | They first signed in with a different method than the one they’re using now. Ask them to sign in the original way, or contact support. |
| Someone whose email isn’t on your domains can’t be added | Invite links, self-claim and card assignment all check the registered domains. There’s no self-serve way to add someone outside them — contact support. |
| You’ve locked yourself out after enabling enforcement | Only Blinq support can switch enforcement back off. Email support@blinq.me from an address on your domain. |
