How to increase SAML clock-skew tolerance in Keycloak (as IDP)?
02:16 24 Nov 2025

I’m following the Autodesk SSO integration guide and configuring SAML metadata mapping, but the mapping keeps failing. https://help.autodesk.com/view/SSOGUIDE/ENU/?pl=KOR

When I asked Autodesk support, they told me their logs show this error:
The current time is before the time-range specified in the Assertion Conditions.

Our server time (NTP) is correct, but Autodesk suggested that we “increase the time-skew tolerance on our IDP side(Keycloak)”.

However, I cannot find any official documentation on how to adjust SAML clock-skew tolerance when Keycloak is acting as the Identity Provider.

Is there any supported way (env var, SPI config, or server setting) to increase SAML clock-skew tolerance in Keycloak IDP?

Thanks in advance!

keycloak single-sign-on autodesk-forge saml-2.0 autodesk