Salesforce SSO Error "The audience in the assertion did not match the allowed audiences"
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

After setting up Salesforce with Secure Assertion Markup Language (SAML), the login flow fails with the following error visible on the Salesforce landing page:

The audience in the assertion did not match the allowed audiences.

 

Applies To
  • Secure Assertion Markup Language (SAML)
  • Salesforce
  • Error
Cause

There are a couple of reasons this issue can occur:

  • The Entity ID in Salesforce is case-sensitive.
  • If configuring this on a sandbox, the entity ID needs to be the production URL.
Solution

Recommended content

No recommended content found...