SSO Debugger
How to setup SSO debugger
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> SSO Debugger
| What is the SSO Debugger? |
|---|
| The SSO Debugger is a workspace-level diagnostic tool for troubleshooting single sign-on (SSO) issues, providing logs of recent SSO login attempts along with tools for generating and decoding Multipass tokens. |
The SSO Debugger enables troubleshooting of SSO-related issues. It maintains logs of recent successful and failed SSO login attempts and provides tools for working with Multipass Token Generation and Decoding. IdeaScale recommends keeping the SSO Debugger enabled at all times.

Role Permissions
- Workspace Administrator: Accesses the SSO Debugger to review the SSO Success/Failure Log and to generate and decode Multipass tokens using the Multipass Token Utils.
- All Other Roles (Administrators, Moderators & Members): Cannot access it.
SSO Success/Failure Log
The SSO Debugger displays logs of recent successful and failed SSO login attempts. This log can be accessed from Settings >> Security >> SSO Debugger. The SSO Success/Failure Log section becomes visible only after an SSO Type has been selected under Workspace Single Sign-On Settings. See Exceptions below.

To view the logs:
- Select the desired log type — Success or Failure.
- Specify the start and end dates for the log to be viewed. See Exceptions below for date range restrictions.
- Select Search.

Multipass Token Utils
The SSO Debugger provides a Multipass token generator and decoder for Multipass-enabled communities. This allows a Multipass Token to be generated, or a token generated by an external system to be decoded, to verify that it works correctly with IdeaScale.

Exceptions
- SSO Type Requirement: The SSO Success/Failure Log section does not appear on the SSO Debugger page until an SSO Type has been selected under Workspace Single Sign-On Settings.
- Log Date Range: Logs older than 30 days cannot be viewed.
Frequently Asked Questions
What does the SSO Debugger track?
Logs of recent successful and failed SSO login attempts, along with tools for generating and decoding Multipass tokens for Multipass-enabled communities.
Why might the SSO Success/Failure Log section not appear on the SSO Debugger page?
Because an SSO Type has not yet been selected under Workspace Single Sign-On Settings. See Exceptions above.
How far back can SSO Debugger logs be viewed?
Up to 30 days. Logs older than 30 days cannot be viewed.
What is the purpose of the Multipass Token Utils?
To generate a Multipass Token or decode a token generated by an external system, verifying that it works correctly with IdeaScale, for Multipass-enabled communities.
Related Articles
- Help Article for Workspace Security
- Help Article for Workspace Single Sign-On Settings
- Help Article for Workspace Authentication
- Help Article for SCIM in IdeaScale
- Help Article for SCIM Audit Logs
Last Updated: August 14, 2026