Keep an existing authorized K16 session open while you test SSO. Use a separate browser profile or private window for the pilot user.
Start with the visible symptom
SAML checks
- Confirm that uploaded content is valid SAML metadata, or that Metadata URL is HTTPS and reachable.
- Confirm SP entity ID and SAML ACS URL in the identity provider.
- Confirm Email attribute mapping matches the exact assertion attribute.
- Review signing and encryption expectations with the identity-provider administrator.
- Disable SLO until basic sign-in works.
OIDC checks
- Confirm that Issuer URL matches the issuer in discovery metadata and tokens.
- Confirm that the exact OIDC redirect URL is allowed in the application.
- Confirm Client ID belongs to that application.
- Rotate Client secret if its state is uncertain.
- Confirm Email claim and Username claim are present in the ID token.
- If discovery is off, validate every manual endpoint URL.
Protect access during recovery
Do not use undocumented authentication paths or share protected values to recover access. Ask
another authorized administrator or K16 Support to correct the provider through the supported
administration flow.
- Do not delete the last working provider during a migration.
- Do not close the administrator session that can still reach Settings > Single sign-on.
- Record the provider name, protocol, time, and displayed error.
- Share metadata and logs only through approved channels after removing protected values.
Replace or delete a provider
Create and validate the replacement first. Then disable the old provider and test again. Delete it only after affected users can sign in and sign out through the replacement.
Deletion can take several minutes to affect sign-in. If you deleted a provider by mistake, contact K16 Support.
Return to SSO overview.