Single Sign-On

Set up Single Sign-On between Zivver and your identity provider.

ZivverAccountKey mismatch: unexpected password prompt despite SSO

A user is prompted to enter their Zivver password instead of signing in seamlessly through single sign-on (SSO), even though SSO works for everyone else in the organization. Some users describe this as an unexpected one-time password (OTP) prompt.

Cause

Zivver matches each user to their account with a ZivverAccountKey, based on a source attribute — typically the Exchange attribute ExternalDirectoryObjectId, which in turn is usually based on objectGUID (on-premises Active Directory) or objectId (Entra ID / Cloud Sync). When the identity provider (IdP) sends a different value for this attribute than the one used to create the account, the SAML response no longer matches the stored ZivverAccountKey. SSO then falls back to:

“Please enter your Zivver password once.”

This mismatch is most often triggered by:

  • An employee who left the organization and later rejoined. The new account gets a new source object ID, which no longer matches the original ZivverAccountKey.
  • A migration from on-premises AD sync to Zivver Cloud Sync, which can change the attribute used for the ZivverAccountKey.

Solution

1. Immediate unblock: reset the user’s password

To let the affected user log in right away, reset their Zivver password:

  1. Log in to the Zivver WebApp.
  2. Click Organization Settings.
  3. Expand User administration.
  4. Click Accounts.
  5. Search for the affected user.
  6. Click .
  7. Scroll down to Security and login.
  8. Click .
  9. Enter a new password.
  10. Leave User must choose another password after the next login unchecked.
  11. Click .

The user can enter this password once at the prompt. SSO then keeps working until a new mismatch occurs — to prevent that, diagnose and fix the root cause below.

2. Diagnose: check whether the IdP returns the correct ZivverAccountKey

  1. Open Chrome.
  2. Install the SAML-tracer extension.
  3. Open the SAML-tracer extension.
  4. Go to https://app.zivver.com.
  5. Enter the email address of the affected user.
  6. Wait for the WebApp to redirect you to the IdP.
  7. Log in with the user’s workplace credentials.
  8. Wait until you see Please enter your Zivver password once.
  9. Switch back to SAML-tracer.
  10. Pause the SAML-tracer.
  11. Search for the line POST https://app.zivver.com/api/sso/saml/consumer/.
  12. Click this line.
  13. Select the SAML tab.
  14. Scroll down in the SAML view until you find the ZivverAccountKey. It looks similar to the snippet below:
<Attribute Name="https://zivver.com/SAML/Attributes/ZivverAccountKey">
    <AttributeValue>573457bc-697c-56db-953c-fz2951e9bcee</AttributeValue>
</Attribute>

Remarks

  • You can see which value is set for ZivverAccountKey:
    <AttributeValue>573457bc-697c-56db-953c-fz2951e9bcee</AttributeValue>.
  • You can check whether the value is correct by using Synctool > Sources > Specific user source > Data preview. The SsoAccountKey column shows the ZivverAccountKey.
  • Do not compare the value with the ObjectGUID in the AD Attribute Editor for this specific user. The Attribute Editor shows a “user friendly” ObjectGUID. You must compare it with the Base64 value of the ObjectGUID.

3. Fix the root cause

If the ZivverAccountKey already matches, but the user still sees the “Please enter your Zivver password once” message, update the ZivverAccountKey with the Synctool. Under Syncing > Synchronization Options, select the special option Update the password/accountkey for all users in local data. For users with the correct ZivverAccountKey, this will not change anything, but you can optionally first set a source filter to only synchronize the affected users.

Warning
Only run a bulk update once you are confident you have identified the correct attribute. An incorrect update can lock users out of SSO. See Manually update the ZivverAccountKey for the full Synctool V2 procedure.

If the ZivverAccountKey does not match, the Synctool and the IdP are using different source attributes. Align them on the same attribute:

  • For Cloud Sync or Entra ID-native setups, standardize on user.objectid. See Check value of ZivverAccountKey in Entra ID to verify this in Entra ID.
  • If on-premises Active Directory remains your source of truth, keep both the Synctool and the IdP on the (Base64-encoded) objectGUID.

You can change the Synctool mapping under Sources > Specific user source > Users, where you can change the attribute that is mapped for ZivverAccountKey. If the IdP is returning the wrong attribute instead, change it in the IdP settings. Once both sides use the same attribute, run the bulk update described above.

4. Confirm the fix

Confirm with recently affected users — leavers/rejoiners and migrated accounts — that SSO now works without a password prompt.