Troubleshooting SSO Org Mismatch Error

Problem

When trying to log in to CircleCI using Single Sign-On (SSO), you may see an sso_org_mismatch error message in your browser's address bar. This error typically occurs when you attempt to use one organization's SSO login credentials to access a different SSO-enabled organization in CircleCI.

SSO (Single Sign-On) is a login method that allows users to access multiple applications with one set of credentials. In CircleCI, each organization can have its own SSO configuration, and users must use the correct SSO login information for each specific organization.

The most common reasons for this error include:

  • Using incorrect SSO login information for the organization you're trying to access
  • Being redirected from a company-level domain that doesn't match the intended organization
  • Having cached login information from a different organization

Solutions

Solution 1: Verify You're Using the Correct SSO Domain

  1. Double-check that you're accessing the correct CircleCI organization URL
  2. Ensure you're using the proper SSO domain for the specific organization you want to access
  3. Each SSO-enabled organization requires its own unique domain - you cannot use one organization's SSO credentials to access another organization
  4. Clear your browser cache and cookies for CircleCI, then try logging in again

Solution 2: Check for Domain Redirects

  1. Verify that your company hasn't set up domain redirects that might be sending you to the wrong organization
  2. Contact your IT administrator to confirm the correct SSO domain for your intended CircleCI organization
  3. If your company uses multiple CircleCI organizations, ensure you have the right domain for each one

Solution 3: Request SSO Reset from Support (For Users)

  1. If you continue experiencing this error after verifying your login information, contact CircleCI Support
  2. Provide your CircleCI username in your support request
  3. Our Support team can reset your SSO connection to resolve the mismatch

Note: You may encounter this error again if you continue using incorrect login information

Solution 4: Remove User from Organization (For Organization Admins)

For Standalone (non-OAuth) Organizations:

  1. Log in to CircleCI as an organization administrator
  2. Navigate to your organization settings
  3. Go to the "People" or "Users" section
  4. Find the affected user and remove them from the organization
  5. This action will reset and disconnect their current SSO connections
  6. The user can then be re-invited to the organization with the correct SSO setup

Note: This solution only applies to standalone organizations. For organizations that are part of larger enterprise setups, contact CircleCI Support for assistance.

Outcome

After trying these troubleshooting steps, you should be able to log in successfully to your CircleCI organization using SSO. If the issue persists:

  • Issue Resolved: You should be able to access your CircleCI organization dashboard without seeing the sso_org_mismatch error
  • Issue Still Occurring: Contact CircleCI Support with your username and organization details for further assistance

Additional Notes

  • Each CircleCI organization with SSO enabled must use its own unique domain and login credentials
  • If you work with multiple CircleCI organizations, bookmark the correct login URLs for each to avoid confusion
  • Browser cache and cookies can sometimes store incorrect SSO information, so clearing them is often helpful
  • Organization administrators have more options for resolving SSO issues than individual users

Additional Resources


If you continue to experience issues after following these troubleshooting steps, please contact CircleCI Support with your username and organization details for personalized assistance.

Was this article helpful?
0 out of 1 found this helpful

Comments

0 comments

Article is closed for comments.