This 403 error occurs when your identity provider isn’t sending a required user attribute — usually contact_phone_number — in the SAML response.
Applies to: SAML SSO integration, customers implementing Invoca’s SAML SSO Setup
Symptoms
- A user sees a 403 error when attempting to log in to Invoca via SAML/SSO.
- The SAML response includes an error message reading “Contact phone number can’t be blank, Contact phone number Invalid.” You’ll need your SSO debugger to see this message.
- This is often the user’s first login attempt via SAML/SSO.
Cause
The user’s configuration in your identity provider (IdP) is missing the required attributecontact_phone_number.
Resolution
- In your identity provider, open the user attributes in your user configuration.
- Confirm the configuration includes:
first_namelast_namecontact_phone_numberorganization_id_from_network— required only if you’re using the optionalorganization_typeattribute and its value is “Advertiser” or “Affiliate”
- Add any missing attributes to the identity provider’s user configuration.