Troubleshoot sign-in, invitations and SSO
Diagnose and fix email verification, password, single sign-on, invitation, seat limit and pending-access problems in a Doxbrix workspace.
Use this page when a person cannot sign in to Doxbrix, cannot accept a workspace invitation, or signs in successfully but cannot reach the workspace. Each entry starts with the message or behavior the person sees, then gives the cause, a check, the fix, and how to confirm recovery.
Most fixes on this page need a workspace Owner or Admin. Start with the least invasive check: ask the affected person for the exact message on screen and the email address they used.
Sign-in problems
"Please verify your email before signing in"
Cause: The account was created with an email address and password, and the address was never confirmed. Doxbrix does not start a session for unverified email and password accounts. Accounts that sign in with Google or SSO are verified automatically.
Check: Ask the person to search their inbox and spam folder for the Doxbrix verification email.
Fix: On the sign-in page, select Resend beside the message to send a fresh link. Doxbrix also sends a new link automatically each time an unverified account tries to sign in. Verification links stay valid for 24 hours, so an older link may have expired. Do not create a second account; resending is always the recovery path.
Confirm: After the person opens the link, Doxbrix signs them in without returning to the sign-in form.
"Invalid email or password."
Cause: The email address or password does not match an account, or the account was created with Google or SSO and has no password.
Check: Confirm the email address has no typing errors and is the one the person signed up with.
Fix: Reset the password from the sign-in page, as described in Sign in and reset your password. If the person normally uses company SSO, have them select Continue with SSO instead.
Confirm: The person reaches the dashboard, or the page they were trying to open.
"requires single sign-on for this email domain"
The full message reads: "Workspace requires single sign-on for this email domain. Use "Continue with SSO" instead."
Cause: The workspace verified the person's email domain for SSO and turned on Require SSO. Password sign-in, and email sign-up, are blocked for every address in that domain.
Fix: Enter the work email and select Continue with SSO. If the person must use a password temporarily, an Owner or Admin can turn off Require SSO in Settings → Single Sign-On; see Set up single sign-on.
Confirm: The identity provider's sign-in page opens and returns the person to Doxbrix.
"Enter your work email first"
Cause: The person selected Continue with SSO with an empty Email field. Doxbrix uses the email domain to find the workspace's identity provider.
Fix: Type the work email address, such as teammate@example.com, then select Continue with SSO again.
"No SSO provider is configured for this email domain"
Cause: No SSO connection matches the domain of the email that was entered, or the connection's domain has not passed DNS verification yet.
Check: An Owner or Admin opens Settings → Single Sign-On and confirms that a connection exists for the domain. A connection that still needs verification shows Get DNS record and Check DNS buttons.
Fix: Select Get DNS record, add the TXT record it shows at your DNS provider, and then select Check DNS. The record host begins with _docflow-sso-; enter it exactly as shown. DNS changes can take time to propagate, so repeat Check DNS if the first check fails. Also check that the person used their work address rather than a personal one.
Confirm: The connection no longer shows the DNS buttons, and Continue with SSO opens the identity provider.
Require SSO cannot be turned on
Cause: Doxbrix enforces SSO only for verified domains. Until at least one connection has a verified domain, the switch refuses the change with "Verify at least one SSO domain before enforcing SSO sign-in."
Fix: Verify the domain with Get DNS record and Check DNS as described above, then turn on Require SSO again.
Single Sign-On settings are locked
Cause: SSO is included only in the Business plan.
Fix: An Owner upgrades the workspace on the Billing page. See Manage billing and change plans and Plans and limits reference.
Access after SSO sign-in
"Access denied" after a successful SSO sign-in
The page reads "You've successfully signed in, but you don't have permission to access this workspace."
Cause: A successful identity provider sign-in proves who the person is but does not grant access. When a person signs in through SSO without a pending email invitation, Doxbrix records them as a pending member with no role. Pending members cannot open the workspace.
Check: An Owner or Admin opens Settings → Members & Invitations. A banner reports how many people "have signed in via SSO and are awaiting access."
Fix: In the members table, choose a role in the Role column, or select Approve and then Approve as Viewer to grant the Viewer role. Remove the member to deny access. To skip this step for future members, invite them by email first: when an invited person signs in through SSO, Doxbrix grants the invited role automatically.
Confirm: The person signs in again and reaches the dashboard. See Manage members and invitations.
Invitation problems
"This invitation has expired. Ask the workspace admin to resend it."
Cause: The invitation link is past its expiry date.
Fix: An Owner or Admin opens Settings → Members & Invitations, finds the invitation under Pending invitations, and selects Resend invitation from its actions.
"This invitation has been revoked." or "This invitation link is invalid."
Cause: An admin revoked the invitation, or the link was copied incompletely.
Fix: Ask the admin to send a new invitation, and open the link directly from the email.
"This invitation has already been accepted."
Cause: The invitation was used once already, possibly by the same person in another browser.
Fix: Sign in normally. If the workspace does not appear, confirm with an admin that the account is listed in Workspace members.
The invitation does not join the workspace after sign-in
Cause: The person signed in with a different email address from the one invited. The sign-in page shows "Sign in with the invited email address to continue the workspace invite."
Fix: Sign out, then sign in or create an account with the exact invited address. If the person should use another address, ask the admin to invite that address instead.
Seat limits
"Editor seat limit reached"
The full message reads "Editor seat limit reached (N). Upgrade your plan or add seats to continue."
Cause: Owners, Admins, and Editors each use an editor seat, and the workspace has used all the seats its plan and add-ons include. Plans include 1 seat on Free, 3 on Starter, 8 on Pro, and 20 on Business.
Check: Open Billing and look at Editor seats in the USAGE SNAPSHOT.
Fix: Choose one of these:
- Invite the person as a Viewer, which does not use an editor seat.
- Change an inactive Editor to Viewer, or remove members who have left.
- Buy extra editor seats as an add-on on a paid plan, or upgrade the plan. See Manage billing and change plans.
Confirm: Send the invitation or change the role again; it completes without the message.
