invalid SAML assertion: audience mismatch" helpdesk fix
Fixes invalid SAML assertion audience mismatch errors: aligning the audience and entity ID between the identity provider and the app. Use when SSO fails naming the audience. Not for signature or clock-skew failures.
TL;DR
The app rejected the SAML assertion because the audience value does not match what it expects. Find the audience the app demands, set the identical value in the IdP app configuration, and SSO succeeds.
The query
"invalid SAML assertion: audience mismatch" helpdesk fixUse this when
- SSO fails with audience mismatch or invalid audience
- the error appears after an app URL or domain change
- metadata import produced a subtly wrong entity ID
Not for
- signature validation failures
- expired assertion errors from clock skew
- attribute or group mapping issues
Steps
- Read the exact audience value the app expects from its SAML configuration or error detail. Expected output: the expected audience string is in hand.
- Open the IdP app settings and find the configured audience or entity ID. Expected output: the configured value is visible for comparison.
- Set the IdP audience to match the app expectation exactly, including scheme, casing, and trailing slash. Expected output: both sides carry the identical string.
- Save and retry SSO. Expected output: the assertion validates and login completes.
- If the app publishes SAML metadata, re-import it to prevent future drift. Expected output: metadata import confirms the audience matches.
Applies to
SAML 2.0 service providers, Okta, Entra ID, or any IdP, current versions.
Variant phrasings
Audience mismatch after moving the app to a new domain
The entity ID still names the old domain; update it everywhere.
Mismatch only in one environment
Each environment needs its own audience value; do not share configs across envs.
Why it happens
The audience tells the app the assertion was meant for it. Any difference, even a trailing slash, makes the app treat the assertion as misdirected and reject it.
Edge cases
- Some apps accept multiple audiences; register all of them rather than swapping.
- Proxy or CDN URL rewrites can change the effective entity ID the app sees.
- After fixing, clear the app session; a cached failed state can persist.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_cmnJyBlh2TuwK-93jTosVg