Loading
Prepare for Email to Become the Default Login ExperienceRead More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Secure Your Salesforce Org
Troubleshoot SAML Assertion Errors

Troubleshoot SAML Assertion Errors

Use the SAML Assertion Validator to troubleshoot single sign-on (SSO) login problems and identify errors in SAML assertions sent by your identity provider.

Required Editions

Available in: both Salesforce Classic and Lightning Experience

Federated Authentication is available in: All Editions

Delegated Authentication is available in: Professional, Enterprise, Performance, Unlimited, Developer, and Database.com Editions

Authentication Providers are available in: Professional, Enterprise, Performance, Unlimited, and Developer Editions

User Permissions Needed
To view the settings: View Setup and Configuration
To edit the settings:

Customize Application

AND

Modify All Data

If users have difficulty logging in after you configure Salesforce as a SAML service provider, use the SAML Assertion Validator to find assertion errors.

Note
Note Some errors stop the validator from continuing, potentially leaving undetected errors. After you fix initial errors, run the assertion through the validator again to ensure that it hasn’t missed anything.
  1. Obtain a SAML assertion in plain XML, base-64 encoded, or deflated and base-64 encoded format from your identity provider.

    If a user can’t log in to Salesforce, the invalid SAML assertion is automatically entered into the SAML Assertion Validator, if possible. Some errors prevent the assertion from being entered automatically.

  2. From Setup, use the Quick Find box to find and select Single Sign-On Settings.
  3. Then click SAML Assertion Validator.
  4. Enter the SAML assertion into the text box, and click Validate.
    Note
    Note If your org has multiple SAML SSO configurations, the validator tries to detect the right one. You can also select a configuration by clicking the dropdown arrow next to Auto detect config.
  5. Share the results of the validation errors with your identity provider.

The validator only detects errors related to the SAML assertion. To troubleshoot errors unrelated to the assertion, view the login history.

 
Loading
Salesforce Help | Article