> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinq.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting SAML SSO

> Sign-in failures, certificate errors, settings you can't reach, and people who can't join.

| Symptom                                                            | Cause and fix                                                                                                                                                                                                                              |
| ------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| The SAML settings show an upgrade prompt, but you're on Enterprise | No domain is registered yet. The SAML settings unlock once Blinq adds at least one domain to your workspace. Email [support@blinq.me](mailto:support@blinq.me) with the domains you want covered.                                          |
| Sign-in fails with a signature or invalid document error           | The identity provider isn't signing the response. In Entra ID, set **Signing Option** to **Sign SAML response and assertion** under SAML Certificates. Entra has been known to reset this, so re-check it if sign-in breaks after working. |
| Sign-in fails after working for months                             | Check the signing option above, and confirm the Blinq application still exists in your identity provider — removing it breaks sign-in for everyone on your domains.                                                                        |
| Sign-in returns a 404                                              | The identity provider values are in the wrong Blinq fields. The sign-on URL goes in **Single Sign-On URL** and the issuer or identifier goes in **Identity Provider Entity ID** — it's easy to swap these two.                             |
| Launching Blinq from the app tile returns a server error           | Starting from the identity provider requires enforcement to be switched on as well. Contact support before enabling it, and see [How SAML SSO works](/identity/how-sso-works).                                                             |
| Someone still sees password and email code options                 | Enforcement isn't switched on, or their address isn't on a registered domain. Enforcement is matched on the email domain someone signs in with.                                                                                            |
| A team member is told their account is already in use              | They first signed in with a different method than the one they're using now. Ask them to sign in the original way, or contact support.                                                                                                     |
| Someone whose email isn't on your domains can't be added           | Invite links, self-claim and card assignment all check the registered domains. There's no self-serve way to add someone outside them — contact support.                                                                                    |
| You've locked yourself out after enabling enforcement              | Only Blinq support can switch enforcement back off. Email [support@blinq.me](mailto:support@blinq.me) from an address on your domain.                                                                                                      |

## Before you enforce

Most of the cases above are avoidable. Stay signed in to Blinq in your main browser while you configure SSO, and run every test in a separate browser or a private window. Only switch on enforcement once a test sign-in has actually succeeded.

## What to send support

If none of these explain it, email [support@blinq.me](mailto:support@blinq.me) with your workspace name, the identity provider you're using, the email address that failed, and roughly when the attempt was made. That's enough to trace the sign-in on the Blinq side.

<hr />

### Need help?

For any questions or issues, [contact Blinq support](https://support.blinq.me/en/) or email [support@blinq.me](mailto:support@blinq.me).
