How to resolve the “Could not validate SAML assertion” error
Admins Updated Nov 17, 2025
In this article
The information in this article applies to all Dropbox users.
An X.509 certificate helps authenticate identity and keep your data secure.
You may see the message, “Could not validate SAML assertion” if your X.509 certificate has expired and your identity provider (IdP) fails to send a valid, signed response. This message is solely informational. Sign-ins can still work as long as the SAML response is valid.
Certificate renewal and enforcement should be managed in your IdP (for example, Okta or Azure Ad), not Dropbox. Managing renewals helps prevent sign-in issues or outages.
To upload a new X.509 certificate:
- Log in to dropbox.com.
- Click Admin console in the left sidebar.
- Click Settings.
- Click the Security tab.
- Under Authentication, click Add to the right of X.509 certificate.
- Select your X.509 certificate from your hard drive, and click Upload.
- Click Save.
Community answers
-
Posted by: Liberty1991 228 days ago
205
5
-
Posted by: TheFlodge 556 days ago
7243
6
-
Posted by: Julie E.1 2815 days ago
14312
15
-
Posted by: tjleyland 2948 days ago
13480
2