IDP Specific

Why do I see “SAML assertion missing required attributes” or users are not matched to WordPress accounts?

3 views 0

Probable Cause:

Keycloak has not been configured to include necessary attributes (such as email, givenName, or surname) in the SAML assertion.

Solution:

  1. In Keycloak admin → Clients → Client Scopes → select your WordPress client.
  2. Go to the Mappers tab.
  3. Click Add Builtin and add attributes such as:
    • X500 email
    • X500 givenName
    • X500 surname to ensure those attributes are sent in the SAML response.
  4. Save mappings.
  5. In WordPress plugin → Attribute/Role Mapping, map the incoming attribute values correctly.

Still need help?

Contact us at samlsupport@xecurify.com

Was this helpful?


Hello there!

Need Help? We are right here!

support