## TL;DR
The app cannot verify Okta's signature on the SAML response, almost always a certificate mismatch, a signing algorithm change, or clock skew. Compare the certificate Okta signs with against what the app trusts, align the algorithm, and retry.

## The query
```text
saml response signature validation failed between okta and the app
```

## Use this when
- SSO fails with signature validation errors
- the error started after a certificate renewal
- one app fails while other Okta apps work

## Not for
- audience or recipient mismatches
- attribute mapping problems
- Okta-side authentication failures

## Steps
1. In Okta, open the app's SAML settings and note the signing certificate fingerprint and algorithm. Expected output: you have the exact cert fingerprint Okta uses.
2. In the app (service provider), check which IdP certificate it trusts and which algorithm it expects. Expected output: the trusted cert and algorithm are visible.
3. If the fingerprints differ, import the current Okta certificate into the app. Expected output: the app now trusts the signing cert.
4. Align the signature algorithm on both sides, typically SHA-256. Expected output: both sides specify the same algorithm.
5. Retry SSO and confirm the login completes. Expected output: the SAML response validates and the user session starts.

## Applies to
Okta SAML 2.0 apps, any service provider supporting SAML, current Okta admin console.

## Variant phrasings
### Validation fails intermittently
Clock skew between the app server and Okta; sync the app server time.

### Fails only for signed assertions vs signed responses
Okta and the app disagree on what is signed; match the authn request expectations.

## Why it happens
SAML trust is cryptographic: the app verifies Okta's signature against a pinned certificate. Renewals change the cert, and if the app still pins the old one, every response fails validation.

## Edge cases
- Okta rotates app certificates on a schedule; calendar the renewal and update the app the same day.
- Some apps cache the IdP metadata; refresh the metadata URL after changes.
- Test with a fresh incognito session; stale sessions mask the fix.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_dd97_ETVR0qggewCsT68sw
