SAML error codes
When an error occurs during a SAML 2.0 flow, AM can redirect the user to the configured SAML error page. You can configure the error page URL and HTTP binding in the common federation configuration. Learn more in Common federation configuration.
Error page parameters
The error page can receive the following parameters:
errorcode-
The error code, which is the key used to look up the error message.
errormessage-
A more detailed, localized error message.
httpstatuscode-
The HTTP status code associated with the error.
With the HTTP-POST binding, AM sends the parameters as form parameters.
With the HTTP-Redirect binding, AM sends the parameters as query parameters.
The available parameters can depend on where the error occurs.
Don’t assume that every error path sends the same parameters.
Some error paths can also provide values such as the originating realm or RelayState.
However, these values aren’t part of a stable, documented contract for every error path.
The error page URL is a global setting that applies to all realms.
You can’t configure it separately for each realm.
Don’t rely on the originating realm, realm alias, RelayState, hosted entity ID, SP entity ID, transaction ID, or correlation ID to select realm-specific error content or branding.
Integrated SAML 2.0 flows that use authentication trees don’t use the same error-reporting mechanism.
SAML 2.0 error codes
The following error-code values are listed by the default SAML 2.0 error page.
The errorcode value identifies the error, and errormessage provides more detail.
| The stability of this interface is classified as evolving. Don’t assume that this list is exhaustive or unchanged across versions. |
-
assertionNotSigned -
cannotFindArtifactResolutionUrl -
errorCreateArtifact -
errorCreateArtifactResolve -
errorDecodeResponse -
errorInSOAPCommunication -
errorMetaManager -
errorObtainArtifact -
errorObtainResponse -
failedToAuthenticateRequesterURI -
failedToCreateArtifactResponse -
failedToCreateAssertionIDRequest -
failedToCreateAttributeQuery -
failedToCreateAuthnQuery -
failedToCreateResponse -
failedToCreateSOAPMessage -
failedToGetAssertionIDRequestMapper -
failedToGetIDPSSODescriptor -
failedToInitECPRequest -
failedToProcessQueryRequest -
failedToProcessSSOResponse -
failedToSendECPResponse -
idpNotFound -
invalidAssertion -
invalidAssertionID -
invalidHttpRequestFromECP -
invalidIDP -
invalidInResponseTo -
invalidIssuer -
invalidMetaAlias -
invalidRequestUri -
invalidSignature -
invalidSOAPMessage -
invalidStatusCode -
largeContentLength -
LogoutRequestCreationError -
LogoutRequestProcessingError -
LogoutResponseProcessingError -
metaDataError -
missingArtifact -
missingArtifactResponse -
MissingSAMLRequest -
missingSAMLResponse -
nameIDMappingFailed -
noRedirectionURL -
notSupportedHTTPMethod -
nullAssertionID -
nullDecodedStrFromSamlResponse -
nullIDPEntityID -
nullIDPMetaAlias -
nullInput -
nullNameID -
nullPathInfo -
nullRequestType -
nullRequestUri -
nullSessionIndex -
nullSessionProvider -
nullSPEntityID -
nullSSOToken -
readerServiceFailed -
requestProcessingError -
requestProcessingMNIError -
singleLogoutFailed -
soapError -
SSOFailed -
UnableToCreateArtifactResponse -
UnableToRedirectToAuth -
unsupportedEncoding