CHW-1109 SSOIdPError

identity provider returned an error or could not be contacted

Default message: identity provider returned an error or could not be contacted
HTTP status: 502 (server)

Problem. The identity provider returned an error response, could not be contacted, or returned a token that failed verification. Cause. IdP outage, misconfigured client ID / secret, clock skew between IdP and Chainsaw, or a malformed discovery document. Fix. Verify the IdP status page and the SSO configuration in /api/orgs/{org}/sso, then retry. HTTP 502.