hi all,
something’s broken in our SAML integration - SCIM provisioning is failing for new users. it’s not a full outage, more… intermittent. been seeing this for the last 24 hours.
we’re on Genesys Cloud, obviously. using the latest SDKs for attribute mapping - v6.1.103.0. the IDP is Okta, configured with the standard attributes, but the uniqueUser attribute isn’t consistently making it through the SAML assertion.
here’s what i’ve checked so far:
- Okta Configuration: Attribute statements in the Okta application are correct.
uniqueUseris mapped to theuserIdattribute, which is populated in the assertion. - Genesys Cloud SAML Settings: SAML settings in GC are pointing to the correct IdP metadata. attribute mapping is set up to pull
userIdinto theuniqueUserfield. - Assertion Debugging: using a SAML tracer, i see some assertions do contain
uniqueUser, and provisioning works fine for those. but roughly 20% of assertions are missing it.
here’s a sample of a failing assertion - stripped down for brevity. it’s missing the uniqueUser completely.
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ...>
<saml2:AttributeList>
<saml2:Attribute Name="firstName">
<saml2:AttributeValue>john</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute Name="lastName">
<saml2:AttributeValue>doe</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute Name="userId">
<saml2:AttributeValue>johndoe123</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute Name="email">
<saml2:AttributeValue>john.doe@example.com</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeList>
</saml2:Assertion>
the error in Genesys Cloud is a generic SCIM error:
| Error Code | Description |
|---|---|
| SCIM-2002 | Invalid input. The request body is missing required attributes. |
i’m suspecting some sort of race condition on the Okta side. it’s driving me crazy.
important: before you suggest anything, please remember we have strict OAuth token rotation policies. all API calls are made with short-lived tokens - we refresh every 15 minutes. it’s not a token issue.
anyone else running into this? is there a known issue with SAML assertions in Genesys Cloud? is there some hidden log i’m missing?