> ## Documentation Index
> Fetch the complete documentation index at: https://docs.peepsai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting single sign-on

> What each single sign-on message means, and how to fix it.

When single sign-on fails, you land back on the Peeps login page with a message. Find it below.

## Messages on the Peeps login page

### "Single sign-on isn't set up for that email"

No SSO connection covers this email's domain. Check that you entered your work email. SSO covers only the exact domains your organization set up: `eu.acme.com` is a different domain from `acme.com`.

### "Single sign-on isn't available for your organization"

SSO isn't switched on for your organization yet, or your domain isn't verified. If you're setting SSO up, finish the DNS step in [Set up Okta](/sso/okta). Otherwise, email [support@peepsai.com](mailto:support@peepsai.com).

### "Your email address isn't on a domain your organization uses for single sign-on"

Okta signed you in with an email outside your organization's domains. Check the email on the person's Okta profile. People on other domains, such as contractors, can't use SSO; invite them to Peeps as usual.

### "Single sign-on has to start from this page"

The sign-in didn't start from the Peeps login page. This happens when you use the Peeps tile on the Okta dashboard, or finish a sign-in in an older browser tab. Choose **Sign in with SSO** on the login page and try again.

### "We couldn't link this sign-in method to your Peeps account yet"

You already have a Peeps account with this email, but it has never been confirmed. Sign in once with a login link (enter your email and choose **Continue**), then SSO works.

### "Single sign-on didn't complete"

Okta's response to Peeps didn't pass our checks. The usual causes:

* The **Audience URI** in the Okta app doesn't exactly match the one we sent you.
* Okta started signing with a new certificate we don't have yet. Email us the app's current metadata.

### "Sign-in didn't complete"

Peeps couldn't finish creating or updating your account. Try again. If it keeps happening, email [support@peepsai.com](mailto:support@peepsai.com).

### You're sent back to the login page with no message

Okta is sending people to the wrong address. In the Okta app, check that **Single sign-on URL** and **Audience URI** match exactly what we sent you, with no leftover placeholder values.

## Messages in Okta

### "User is not assigned to this application"

The person is in your Okta organization but isn't assigned to the Peeps app. On the app's **Assignments** tab, assign them or a group they belong to.

## The DNS record isn't found

If we can't see your TXT record, check it yourself. Replace `acme.com` and the host name with yours:

```bash theme={null}
dig +short TXT _better-auth-token-acme-1a2b3c4d-saml.acme.com
```

It should print the token. If it prints nothing:

* **The host name is doubled.** Your DNS provider added your domain to a name that already included it. Check with the command below. If it prints the token, edit the record so its host is only `_better-auth-token-…-saml`.

  ```bash theme={null}
  dig +short TXT _better-auth-token-acme-1a2b3c4d-saml.acme.com.acme.com
  ```

* **The change hasn't appeared yet.** Most providers publish within minutes. If someone looked the name up before the record existed, some DNS servers remember "not found" for up to an hour or so.

* **The DNS lives elsewhere.** Records only take effect at the provider your domain actually uses. `dig +short NS acme.com` shows which one that is.

Still stuck? Email [support@peepsai.com](mailto:support@peepsai.com) with the message you see and the email you signed in with.
