Skip to main content
This 403 error occurs when your identity provider isn’t sending a required user attribute — usually contact_phone_number — in the SAML response.
Applies to: SAML SSO integration, customers implementing Invoca’s SAML SSO Setup

Symptoms

  • A user sees a 403 error when attempting to log in to Invoca via SAML/SSO.
  • The SAML response includes an error message reading “Contact phone number can’t be blank, Contact phone number Invalid.” You’ll need your SSO debugger to see this message.
  • This is often the user’s first login attempt via SAML/SSO.

Cause

The user’s configuration in your identity provider (IdP) is missing the required attribute contact_phone_number.

Resolution

  1. In your identity provider, open the user attributes in your user configuration.
  2. Confirm the configuration includes:
    • first_name
    • last_name
    • contact_phone_number
    • organization_id_from_network — required only if you’re using the optional organization_type attribute and its value is “Advertiser” or “Affiliate”
  3. Add any missing attributes to the identity provider’s user configuration.
See the Attribute Mappings Reference in SAML SSO Setup for the full list of attributes Invoca requires or accepts.

Where to go next

SAML SSO Setup

Configure SSO with Okta

403 Error Logging Into Invoca via SAML/SSO: Invalid Signature

Last modified on September 24, 2026