SAML checklist
- The user is assigned to the provider application.
- Entity ID, reply or assertion URL, and sign-on values match Biqli exactly.
- The current signing certificate is active and not expired.
- Required email and identity attributes use the expected claim names.
- Provider and Biqli clocks are accurate enough for assertion validity.
SCIM checklist
- The base URL and bearer token come from the current Biqli configuration.
- Provisioning is enabled for the intended users or groups.
- The provider log shows whether create, update, or deactivate failed.
- A previous account with the same identity is not causing a conflict.
- Token rotation was completed on both sides.

