Probable Cause:
The Valid Redirect URIs (or Assertion Consumer Service URL) in the Keycloak client is not configured exactly as the ACS URL provided by the miniOrange plugin.
Solution:
- Open the miniOrange plugin → Service Provider Metadata tab, and copy the ACS URL.
- In the Keycloak admin console → Clients → your configured client → Settings.
- Paste the ACS URL exactly into the Valid Redirect URIs field.
- Save the client configuration.
Still need help?
Contact us at samlsupport@xecurify.com