A user sees a 403 error when attempting to log in to Invoca via SAML/SSO.
The SAML response includes an error message reading “Invalid Signature on SAML Response,” and the x509 certificate isn’t included in the response. You’ll need your SSO debugger to see this message.
Your identity provider (IdP) has a setting that controls whether your x509 certificate is included in the SAML response sent to Invoca. If that setting isn’t enabled, Invoca can’t validate the signature.