How to move your network from Invoca’s legacy SAML single sign-on to the new, self-service Next-Gen SSO setup.
What’s changing
Invoca is upgrading its Single Sign-On (SSO) infrastructure. Next-Gen SSO replaces manual configuration with a guided setup wizard for connecting your Identity Provider (IdP). During the migration window, only one SSO connection (Legacy or Next-Gen) is active at a time, and you can freely switch back to Legacy if you run into a problem.
Your users’ login experience, your SSO enforcement mode (Disabled/Optional/Mandatory), your default role settings, and your existing user accounts and roles all carry over unchanged.
Prerequisites
- You must have the Network Super role (Invoca’s highest-level user role) to access SSO settings.
- You need administrator access to your company’s Identity Provider. Supported providers include Okta, Microsoft Entra ID (Azure AD), Google Workspace, ADFS, PingFederate, Auth0, Keycloak, and other SAML 2.0 or OIDC-compatible providers.
- If you already have SAML SSO configured on the legacy system, keep it running until you’ve fully tested your new Next-Gen SSO connection.
- The Next-Gen SSO setup link expires after 8 hours. This window covers only the configuration and mapping process — switching your network over to actually use the new connection is a separate step you can complete afterward.
Step 1: Open SSO settings
Log in to Invoca and go to Settings > Users. Click the kebab menu (⋮) near the top right and select SSO Settings to confirm your current SSO enforcement mode.
Step 2: Generate your Next-Gen SSO setup link
- Locate the Next-Gen SSO section in the SSO Settings pane.
- Enter a friendly name for your connection. This is strictly for your own bookkeeping and isn’t related to the implementation.
- If your Identity Provider is Microsoft Entra ID, select the EntraID checkbox. If not, leave it unchecked.
- Click Begin SSO Setup. Invoca generates a time-limited setup link and opens the Next-Gen SSO Setup Wizard in a new browser tab.
The setup link is valid for 8 hours from the moment you click the button. If the wizard session times out, return to the SSO Settings pane and click the button again to generate a new link — any progress you saved is preserved.
Step 3: Complete the setup wizard
The wizard has five steps:
- Create Application — follow the on-screen instructions to create a new SSO application in your IdP.
- Set Up SAML — the wizard displays a Single Sign-On URL (also called ACS URL or Reply URL) and a Service Provider Entity ID (also called Audience URI). Copy both values; you’ll paste them into your IdP. OIDC connections configure equivalent values differently within the wizard.
- Configure Connection — paste your IdP’s metadata URL (recommended) or enter your Sign-In URL, Sign-Out URL, and certificate manually, then click Create Connection.
- Assign Access — select which users or groups in your IdP should have SSO access to Invoca.
- Test SSO — run the built-in login test before switching your users over.
Step 4: Update your Identity Provider
In your IdP’s existing Invoca SAML application, update only two values with what you copied in Wizard Step 2: the Single Sign-On URL / ACS URL and the Entity ID / Audience URI. Leave your existing attribute mappings unchanged — Next-Gen SSO uses the same attribute names Invoca has always used (first_name, last_name, email, and others), and required attribute names are case-sensitive.
Step 5: Confirm the connection and switch over
Return to the SSO Settings pane. Once your connection shows Ready (refresh the page, or press Edit SSO Configuration and Enable if it still shows Setup Incomplete), find the SSO Logins drop-down and change it from Legacy to Next-Gen, then click Save and confirm.
Test your connection
Open an incognito or private browser window, go to your Invoca login page, and continue to SSO login. Confirm you’re redirected to your IdP, can authenticate, and are returned to Invoca successfully.
Troubleshooting
- Certificate mismatch error: Your IdP’s signing certificate doesn’t match what Next-Gen SSO has on file, often after a certificate rotation. Re-run the setup wizard and re-enter your IdP’s metadata or certificate.
- Missing attributes error: A required attribute (like
first_name or last_name) isn’t present in your IdP’s SSO assertion. Check your IdP’s attribute configuration.
- Setup link expired: Click Edit SSO Configuration in SSO Settings for a new 8-hour link; your progress is saved.
- Locked out: Contact Invoca Support immediately. Support can disable SSO enforcement on your network to restore password-based access while you troubleshoot.
Currently logged-in users aren’t affected when you switch providers — the change applies only to the next login attempt. You can revert to Legacy SSO at any time during the migration window by changing the SSO Logins setting back; you’ll get advance notice before Legacy is retired for good.Last modified on October 1, 2026