Troubleshooting

SSO Login Issues

Troubleshooting Single Sign-On errors and access problems for organisations using SSO.

4 min read

SSO Login Issues

This guide is for users and administrators troubleshooting problems with Single Sign-On (SSO) login on DottSign.

SSO is available on the Enterprise plan only. If you're not sure whether your organisation uses SSO, contact your IT department.


Error: "No SSO configuration found for this email domain"

Cause: DottSign looked up the domain in your email address (e.g., @yourcompany.com) and didn't find an SSO configuration associated with it.

Possible reasons:

  • SSO has not been configured for your organisation yet
  • You entered a different email domain from the one registered with DottSign (e.g., using a personal email instead of your work email)
  • The SSO configuration was recently changed or deleted by your admin

What to do:

  1. Confirm you're using your work email (the one registered with your organisation's identity provider)
  2. Ask your DottSign administrator to verify the SSO configuration in Settings → Security → SSO
  3. If SSO is not yet set up, contact support@dottsign.com for setup assistance

Error: "SSO sign-in failed. Please try again or contact your administrator."

Cause: The authentication attempt was completed at your identity provider (IdP) but DottSign couldn't verify the response.

Common causes and fixes:

CauseFix
Certificate mismatchAdmin should re-download the IdP metadata and re-upload it in DottSign SSO settings
Clock skew between serversEnsure your IdP server's clock is synchronised (NTP), SAML assertions are time-sensitive
Incorrect ACS URLThe Assertion Consumer Service URL in your IdP should be https://app.dottsign.com/auth/sso/{your-org-slug}/callback (replace {your-org-slug} with your organisation's DottSign slug, visible in the SSO settings page)
User not provisioned in IdPCheck that the user exists and is active in your identity provider
Missing email attributeThe IdP's SAML response must include the user's email. Check the attribute mapping in your IdP configuration

Error: "Your organisation requires SSO login"

Cause: Your organisation's DottSign account has SSO enforcement enabled, users cannot log in with passwords or Google, only via SSO.

This is by design. Use the SSO flow:

  1. On the login page, click Continue with SSO
  2. Enter your work email
  3. You'll be redirected to your company's login page

If SSO is not working, contact your IT team, they control the identity provider.


Setting Up SSO for the First Time (Admins)

DottSign supports SAML 2.0 and OIDC identity providers, including:

  • Okta
  • Microsoft Azure AD / Entra ID
  • Google Workspace
  • Auth0
  • OneLogin

SAML Setup steps

  1. Log in to DottSign as an Owner or Admin
  2. Go to Settings → Security → SSO Configuration
  3. Download the DottSign SAML metadata file
  4. Import it into your IdP as a new application/service provider
  5. Configure attribute mapping, your IdP must send:
    • email (required)
    • firstName (recommended)
    • lastName (recommended)
  6. Copy the IdP metadata URL from your IdP
  7. Paste it into DottSign's SSO configuration and click Save
  8. Click Test SSO to validate the connection before enforcing it

Enabling SSO enforcement

Once SSO is working, you can enforce it so all users must log in via SSO:

  • Settings → Security → SSO → Enforce SSO → toggle on

Test SSO with your own account before enforcing, if the configuration is broken, enforcement can lock all users out.


Users Can't Access DottSign After SSO Enforcement

If SSO enforcement was enabled and now users can't log in:

  1. The Account Owner can always log in using their email and password (SSO enforcement doesn't affect the Owner)
  2. The Owner can temporarily disable SSO enforcement in Settings → Security → SSO
  3. Fix the IdP configuration and test again before re-enabling

If the Owner is also locked out, contact support@dottsign.com with your account's domain name and we'll assist with emergency access restoration.


Automatic User Provisioning (JIT)

With SSO enabled, users who don't yet have a DottSign account are automatically provisioned the first time they log in via SSO, no manual invitation needed.

Their role defaults to Member. An Admin can change their role after their first login.


Was this helpful?
Our support team usually replies within 1 business day.
Contact support
Related articles
SSO Login Issues · DottSign Help · DottSign