SSO & Login Troubleshooting
Get back to work fast: resolve login issues, magic link delivery problems, and SSO configuration errors
Written By Nira.app
Last updated 15 days ago
Who This Article Is For
This guide addresses two audiences:
External guests & reviewers: You've been invited to view an asset in Nira and can't get in (go to Part 2)
IT administrators: You're setting up SSO for your enterprise team (go to Part 3)
Both groups will find troubleshooting strategies in Part 2; Part 3 is for IT admins only.
Part 1: Login Methods — A Quick Comparison
Nira offers three authentication methods. Confusion between them causes roughly one-third of all login tickets we receive, so let's be clear about each.
Magic Link (Passwordless)
You get an email with a secure link. Click it, and you're logged in—no password required.
When you'll use this:
Someone shares an asset link with you
You're accessing Nira for the first time
You're a trial user or external reviewer
How it works:
You receive an email: "You're invited to view an asset in Nira"
Click the link in the email
You're logged in instantly to that asset
The link expires after 24 hours
Best for: One-time viewers, external guests, anyone who just needs to see something once.
Username & Password
You create a password when you sign up. Log in at nira.app with email + password whenever you need access.
When you'll use this:
You're a regular team member
You need access to multiple assets
Your company doesn't use SSO
How it works:
You sign up at nira.app/signup and set a password
Later, you visit nira.app and log in with email + password
You can reset your password anytime if you forget it
Passwords can be changed in Account Settings
Best for: Frequent users, team members, anyone who needs persistent access.
SSO (Single Sign-On)
Your IT team configures this. You log in using your company's identity system (Okta, Azure AD, Google Workspace). No separate Nira password.
When you'll use this:
Your company has an Enterprise plan
Your IT team has set up SSO
Your organization uses a corporate identity provider
How it works:
You visit nira.app
You click "Sign in with Okta" (or your provider)
You log in with your corporate email/password
You're automatically redirected to Nira
Best for: Large teams, security-conscious organizations, enterprises with centralized identity management.
Important: SSO is only available on Enterprise plans.
Part 2: Troubleshooting Login Issues
Problem: Magic Link Not Arriving
You clicked "Send me a link," but the email never showed up.
Cause 1: Email Address Was Wrong
The link went somewhere, but not to an inbox you're checking.
What to do:
Double-check the email you entered—any typos?
If you have multiple email accounts, check all of them (including spam, promotions, and updates folders)
Go back to nira.app/login and request a fresh link
Enter your email carefully this time
Wait 2–3 minutes for the email to arrive (email can be slow during peak hours)
Cause 2: The Email Got Filtered to Spam
It was delivered, but your email provider hid it.
What to do:
Check your spam, promotions, and updates folders
Look for a message from
noreply@nira.appIf you find it, mark it "not spam" to whitelist future Nira emails
Check your email filtering rules (Gmail, Outlook, etc.)
Request a new link and check again
Cause 3: The Email Doesn't Exist in Nira
This email address has never been registered or invited.
What to do:
If accessing a shared asset for the first time:
Confirm the email address from the person who shared the link
Request a new link using that exact email address
If trying to log into your own account:
Check what email you used when you signed up
Verify you registered on Nira (not a different service)
Create a new account if needed at nira.app/signup
Cause 4: Your Email System Blocked It
Corporate firewall, ISP, or email provider rejected the message.
What to do:
If you're on a corporate network, contact your IT team and ask them to whitelist
noreply@nira.appAsk IT to check firewall rules
If possible, try requesting the link from a personal email account
Email support@nira.app with your email address and ask for a manual resend
Cause 5: The Invite Link Itself Expired
If someone shared an asset with you, that original invite link may have expired.
What to do:
Ask the person who shared the asset to send you a fresh invite link
A new invite generates a new magic link email
If this is a trial signup, try nira.app/signup again
Problem: Magic Link Expired or Invalid
You clicked the link but got an error saying it's invalid or expired.
Cause 1: More Than 24 Hours Have Passed
Magic links expire after 24 hours for security. This is the most common reason links stop working.
What to do:
Request a new link:
For a shared asset: Ask the person who shared it to resend the invite
For your account: Go to nira.app/login and request a fresh link
Click the new link right away (don't wait around)
Once you click it, the session stays active even if you close the browser tab
Cause 2: You Used a Different Email Address
The link was created for one email but you're trying to use it on another.
What to do:
Check which email you used to generate the link originally
Request a new link using that exact same email
If you need to use a different email, ask the account owner to add it to the invite
Cause 3: Cookies Are Disabled in Your Browser
Nira needs cookies to keep you logged in. Without them, the link won't work.
What to do:
Check if cookies are enabled for nira.app in your browser settings
Temporarily enable cookies
Request a new link and click it
(You can disable cookies again after logging in if you want)
Cause 4: You Clicked the Link on a Different Device
The link was created on one device but you're clicking it on another (rare, but possible if your browser syncs across devices).
What to do:
Find the link in your original email
Copy and paste it directly into the address bar of the device where you want to log in
Don't rely on auto-fill or synced tabs
If it still doesn't work, request a new link
Problem: Stuck in a Login Loop
This is the #1 login issue we see. You click the login button, enter your email, receive a magic link or enter a password, and then—boom—you're back at the login page. Repeat. Repeat. Repeat.
The root cause is always a mismatch between how your account was created and how you're trying to log in. Here are the three scenarios.
Cause 1: Your Account Uses Magic Link, But You're Trying to Use a Password
This is the most common scenario. Your account was created via a magic link (because someone invited you), but later you tried to log in the normal way with a password.
How this happens:
Someone shares an asset with you via a magic link
You click the link, get auto-logged in (magic link = instant login)
Days or weeks pass
You try to log back in at nira.app the "normal" way by typing your email and password
Nira doesn't recognize a password on your account, so it keeps sending you back to "Send me a link"
You're caught in the loop
How to fix it:
Do NOT use a password—your account doesn't have one
Go to nira.app/login and choose "Send me a link"
Check your email for the magic link
Click it to log in
Once logged in, go to Account Settings → Change Password to set a password (so you can log in normally next time)
Cause 2: Your Account Uses Password, But You Keep Requesting Magic Links
You created your account with a password, but you forgot it and kept requesting magic links instead of resetting.
How this happens:
You created a Nira account with email + password
You forget your password
You go back to the login page and think, "Oh, I'll just request a magic link instead"
You request a magic link and click it—and you get logged in
But now you don't see a password option, so you request another link
Loop
How to fix it:
Go to nira.app/login
Click "Forgot your password?" (NOT "Send me a link")
Enter your email
Check your email for a password reset link (it expires after 1 hour)
Click the reset link and create a new password
Log in with email + new password
Cause 3: Your Company Uses SSO, But You're Typing Your Email/Password
Your IT team has set up SSO, but you're ignoring the "Sign in with [Provider]" button and trying to log in the old way.
How this happens:
Your IT team configures SSO (Okta, Azure AD, Google Workspace)
You go to nira.app and see a new "Sign in with Okta" button
You ignore it and type your email address into the login form instead
Nira recognizes you're in an SSO organization and redirects you to your identity provider
You log in at the identity provider
You're redirected back to nira.app
But you're still at the login screen (loop)
How to fix it:
Go to nira.app
Look for the button that says "Sign in with Okta" or "Sign in with Azure AD" or your provider's name
Click that button (do NOT type your email into the login form)
Log in with your corporate credentials
You'll be automatically redirected into Nira
Problem: Password Reset Not Working
You clicked "Forgot your password?" but didn't get a reset email, or the reset link isn't working.
Cause 1: Reset Email Went to Spam
The email was sent but filtered away.
What to do:
Check spam, promotions, and updates folders
Look for email from
noreply@nira.appwith subject "Reset Your Password"Mark Nira emails as "not spam" to whitelist them
Request a new reset link
Cause 2: Reset Link Expired
Password reset links only work for 1 hour. If you wait longer, they're no good.
What to do:
Go to nira.app/login → "Forgot your password?"
Request a new reset link
Click the new link immediately (within 1 hour)
Create your new password
Cause 3: Email Doesn't Have a Nira Account
You entered an email that isn't registered in Nira.
What to do:
Confirm you're using the correct email (ask your account admin if unsure)
If you have multiple email accounts, try each one
If none work, create a new account at nira.app/signup
Cause 4: Your Account Uses SSO Instead of Password
If your company uses SSO, your account doesn't have a password at all. You can't reset something that doesn't exist.
What to do:
Don't try to set a password
Log in via SSO: Go to nira.app and click "Sign in with [Your Provider]"
If you really need password login, contact your IT admin to disable SSO for your account (not recommended)
Problem: Browser-Specific Login Issues
Issue: Can't Log In from Incognito/Private Mode
Incognito mode blocks cookies by default, and Nira needs cookies to work.
What to do:
Log in from regular (non-incognito) mode instead
Or, allow cookies for nira.app in your browser's incognito settings
Issue: Login Works on One Browser but Not Another
Different browsers have different cookie, cache, and extension settings.
What to do:
Clear cookies and cache for nira.app:
Chrome: Settings → Privacy → Clear browsing data → check "Cookies and other site data"
Safari: Develop → Clear Caches (or Settings → Privacy → Manage Website Data)
Firefox: Settings → Privacy → Cookies and Site Data → Clear
Try logging in again
Disable browser extensions (ad blockers, VPNs, password managers can interfere)
Try a different browser entirely (Chrome, Safari, Firefox, Edge)
Issue: Login Fails on Mobile or Tablet
Device or network issue preventing login on mobile.
What to do:
Check that your device has working internet
Try incognito/private mode on your mobile browser
Clear cookies: Settings → Apps → [Your Browser] → Clear Cache/Cookies
Try a different mobile browser (Chrome vs. Safari)
If it's a shared corporate device, contact IT about browser security policies
Part 3: SSO Setup for IT Administrators
Prerequisites
Enterprise plan (SSO is not available on Individual or Professional plans)
Administrator access to your identity provider (Okta, Azure AD, Google Workspace, or SAML-compliant system)
Administrator access to Nira organization settings
How SSO Works (High Level)
You configure an app/integration in your identity provider (Okta, Azure, Google, etc.)
You provide Nira with connection details from your provider
Your identity provider provides Nira with connection details back
Users log in at nira.app, see your provider's login button, and authenticate with their corporate credentials
Nira receives confirmation from your provider and grants access
Users must still be invited to Nira manually (email is the unique identifier). Automatic user provisioning (SCIM) is not supported.
SSO Setup: Okta
Required configuration values:
Single sign-on URL:
https://nira.app/saml/acsAudience URI:
https://nira.app/saml/metadataName ID format: EmailAddress
Steps:
In Okta Admin Console, go to Applications → Create App Integration
Choose SAML 2.0
Enter app name:
NiraOn the "Configure SAML" page, enter the values above
Under Attribute Statements, map:
email→user.email(required)firstName→user.firstName(optional but recommended)lastName→user.lastName(optional but recommended)
Complete the integration and download the SAML metadata XML
Provide the metadata XML to support@nira.app
Go to Users → Assignments and assign users to the Nira app
Assigned users will see "Nira" in their Okta dashboard
Common issues:
"The Application instance is not assigned to the user" — The user must be explicitly assigned in Okta's Nira app (step 8)
"Invalid credentials" — Verify your email attribute mapping is correct
Logout issues — Okta logout configuration must be set up separately; contact Nira support
SSO Setup: Azure AD
Required configuration values:
Identifier (Entity ID):
https://nira.app/saml/metadataReply URL (ACS):
https://nira.app/saml/acsSign on URL:
https://nira.app/login
Steps:
In Azure Portal, go to Enterprise Applications → New Application
Search for "Nira" in the gallery. If available, add it directly. If not, create a custom SAML application.
For custom apps, go to Single sign-on and configure Basic SAML Configuration with the values above
Under User Attributes & Claims, ensure these mappings exist:
email→user.mail(required)firstName→user.givenname(optional but recommended)lastName→user.surname(optional but recommended)
Download the SAML metadata XML
Provide the metadata XML to support@nira.app
Go to Users and groups → Add user/group and assign users to the Nira app
Assigned users will see "Nira" in their Azure apps portal
Common issues:
"User is not assigned to the application" — Users must be explicitly assigned (step 7)
"SAML token not valid" — Ensure the system clocks on your identity provider and Nira are synchronized (within 5 minutes)
Email not populating in Nira — Verify email claim mapping; may be
mail,userPrincipalName, ormailNickname
SSO Setup: Google Workspace
Required configuration values:
ACS URL:
https://nira.app/saml/acsEntity ID:
https://nira.app/saml/metadataName ID format: Email
Name ID: Basic Information → Primary email
Steps:
In Google Admin Console, go to Apps & services → SAML apps
Create a new SAML application for Nira
Enter the Service provider details above
Set up Attribute mapping:
email→ Primary Email (required)firstName→ First Name (optional but recommended)lastName→ Last Name (optional but recommended)
Download the SAML metadata XML and send to support@nira.app
Enable the app for your organization or specific organizational units (OUs)
Users in assigned OUs will see "Nira" in their Google app launcher
Common issues:
"Unable to verify SAML response" — Re-download the latest metadata from Google and provide updated XML to Nira
Users not appearing in Nira — Confirm users are in an OU where the Nira app is enabled
Email domain mismatch — Ensure users are using @domain email addresses and that domain is verified in Google Workspace
SSO Setup: Generic SAML
For identity providers not listed above, use these generic SAML values.
Required configuration values:
Entity ID:
https://nira.app/saml/metadataAssertion Consumer Service (ACS) URL:
https://nira.app/saml/acs
Required attributes:
urn:oid:0.9.2342.19200300.100.1.3(email)urn:oid:2.5.4.42(first name, optional but recommended)urn:oid:2.5.4.4(last name, optional but recommended)
Steps:
Create a new SAML application/integration for Nira in your identity provider
Enter the Entity ID and ACS URL above
Map user attributes (email is required; first/last name recommended)
Generate and download the SAML metadata XML
Provide the metadata XML to support@nira.app
Test with a pilot user before rolling out organization-wide
SSO Troubleshooting
Problem: Users Stuck in Redirect Loop
Users see the login screen repeatedly, or keep being redirected between Nira and the identity provider.
Cause 1: SAML metadata is out of date or incorrect
Fix:
Download the latest metadata from your identity provider
Provide the updated metadata to support@nira.app
Have users test in a fresh incognito session
Clear related cookies: nira.app, okta.com, microsoft.com, or google.com (depending on provider)
Cause 2: User isn't assigned to the Nira app in the identity provider
Fix:
In your identity provider, assign the user to the Nira application/group:
Okta: Applications → Nira → Assignments → Add user
Azure AD: Enterprise Applications → Nira → Users and groups → Add user/group
Google Workspace: Admin Console → Apps & services → Nira → Assign to organizational unit
Have the user log out of their identity provider and back in
Test login in a fresh incognito session
Cause 3: Email attribute mapping is incorrect
Fix:
Verify the email attribute is mapped correctly (see setup guides above)
Test with an admin account first to isolate the issue
Check the attribute name—common variations are
email,mail,userPrincipalNameNira requires a valid email; it won't fall back to other fields
Problem: "This User Does Not Have Permission to Access Nira"
User exists in the identity provider but cannot log into Nira.
Cause: The user hasn't been assigned to the Nira application/group in the identity provider.
Fix:
Assign the user in your identity provider using the steps in the redirect loop troubleshooting section above
Have the user log out of the identity provider and back in
Have the user try logging into Nira again
Problem: User Logs In Successfully but Can't See Any Assets
User successfully authenticates via SSO but has no access to content.
Cause 1: User hasn't been added to teams or granted asset access in Nira
Fix:
In Nira organization settings, add the user to a team or grant them access to specific assets
User logs out and back in
Assets should now be visible
Cause 2: User's role is too restrictive
Fix:
Check the user's role in Nira: Organization Settings → Users → [User Name]
Verify they have an appropriate role (Viewer, Contributor, Team Member, or Administrator)
Update the role if needed and have the user log in again
Problem: Automatic User Provisioning Isn't Working
Users are added to the identity provider but aren't automatically appearing in Nira.
Important: Nira does not support automatic user provisioning (SCIM). Users must be manually invited or added.
Fix:
Manually invite users in Nira: Organization Settings → Users → Invite
Send invites to the same email addresses they use in the identity provider
Users log in via SSO with those email addresses
After first login, the user is created in Nira and persists for future logins
This is a one-time setup per user
Technical Notes
Session expiry: Magic links expire after 24 hours. Password reset links expire after 1 hour. Active sessions remain valid until logout or browser cache clear.
SAML is time-sensitive: Your identity provider and Nira servers must have clocks synchronized within 5 minutes, or SAML authentication will fail.
Email is the unique identifier: All authentication methods (magic link, password, SSO) use email as the account identifier. A user can't have two accounts with the same email.
Cookies are required: Nira requires cookies to be enabled. Incognito/private browsing mode disables cookies by default.
SSO is organization-wide: Once SSO is configured, all users with matching email domains should use SSO. Mixing SSO and password login for the same organization is not recommended.
No automatic provisioning: Nira does not support SCIM or other automatic user provisioning protocols. Users must be invited manually or via group assignment in the identity provider.
Related Articles
User Management & Roles — Adding, removing, and managing team members and their permissions
Plans & Feature Comparison — SSO availability and plan details
Private Sharing & Guest Access — Controlling who can view and edit shared assets
Public Links & Inspector Mode — Sharing without requiring Nira login
Sharing Troubleshooting — Issues with recipients accessing shared content