TrustPortDocs
In the dashboardTest SSO

What it checks

CheckWhat “passing” means
OIDC discovery documentApps and identity providers can find your endpoints automatically.
ID token signing algorithmTokens are signed with an algorithm standard libraries accept (RS256).
JWKS signing keysYour public keys are published, so anyone can verify your tokens.
Organization SSO connectionsEach organization with SSO is Ready, or the reason it isn’t is listed.
Login providersWhich social providers are switched on.

Fixing an organization that isn’t ready

Diagnostics saysDo this
no provider selectedEdit the organization and choose its identity provider.
no verified domainAdd at least one email domain to the organization.
connection not activeEdit the organization and tick SSO active.

Common problems

SymptomLikely cause
“Each domain can belong to only one organization”Another organization already claims that domain. Remove it there first.
The Admin Portal link says it has expiredLinks last 30 minutes. Generate a new one.
A social button doesn’t appearThe provider is switched off or has no credentials. See Social login.
People are told to “ask an administrator for an invitation”They have no account and self-service sign-up is off.
Sign-in is refused with “blocked by a security policy”One of your actions denied it. Check the audit log for the reason.
© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.