---
title: Troubleshooting your white-label portal
description: Lists the most common white-label problems, from DNS and certificates to token sign-in and the Partner API, with the cause and what to do.
---

[Skip to content](https://knowledge.qvalia.com/white-label-troubleshooting#main-content)

- [English](https://knowledge.qvalia.com/white-label-troubleshooting)
- [Svenska](https://knowledge.qvalia.com/sv/felsok-white-label-portalen)

English

Show submenu for translations

[Submit a ticket](https://knowledge.qvalia.com/kb-tickets/new?hsLang=en) [Customer portal](https://servicedesk.qvalia.com/tickets?hsLang=en)

![Qvalia Logo New Blue transparent.png\]](https://knowledge.qvalia.com/hs-fs/hubfs/Qvalia%20Logo%20New%20Blue%20transparent.png?height=24&name=Qvalia%20Logo%20New%20Blue%20transparent.png)

Open main navigation

Close main navigation

- - [English](https://knowledge.qvalia.com/white-label-troubleshooting)
    - [Svenska](https://knowledge.qvalia.com/sv/felsok-white-label-portalen)

  English
  
  Show submenu for translations
- [Submit a ticket](https://knowledge.qvalia.com/kb-tickets/new)
- [Customer portal](https://servicedesk.qvalia.com/tickets)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.qvalia.com/?hsLang=en)
2. [Partner](https://knowledge.qvalia.com/partner?hsLang=en)

# Troubleshooting your white-label portal

## Most white-label problems come from a DNS record added at the wrong time, a sign-in parameter that does not match the account, or a feature that is not active on the account. Find your symptom below.

Check the service status at [qvalia.com/system-status](https://qvalia.com/system-status) first if several customers are affected at the same time.

### Domains, certificates and DNS

 Symptom

 Cause

 What to do

 Your hostname shows an error page

 The routing record was added before Qvalia released the portal

 Wait for Qvalia to confirm the release. Keep the record and notify Qvalia so the hostname can be verified.

 The certificate was never issued

 The validation record was not added within 24 hours, and the certificate request expired

 Contact Qvalia to get a new validation record, and add it within 24 hours.

 The validation record is added but the certificate is still not issued

 The name was entered with the domain twice, the underscore is missing, or your CAA records do not allow Amazon as certificate authority

 Check the record with `dig CNAME +short`. If your DNS provider appends the domain, enter only the part before it. Allow `amazon.com` in your CAA records.

 The portal worked but has become unreachable, with a certificate error

 The validation record was removed, so the certificate could not be renewed

 Add the validation record again and notify Qvalia. Keep it permanently.

 Your DNS provider will not accept the routing CNAME

 The hostname already has A or AAAA records, or you are using the bare apex domain

 Remove the existing A and AAAA records for the hostname. Use a subdomain, for example `portal.your-brand.com`.

 A DNS correction takes long to take effect

 The TTL on the record is long

 Use a short TTL, for example 300 seconds, during setup.

### Sign-in

 Symptom

 Cause

 What to do

 The portal does not load inside your application

 The portal cannot be embedded, for example in an iframe. Its security policy blocks framing.

 Open the portal in a new browser tab or window from a button or link.

 A user cannot sign in with Qvalia portal login

 The user does not exist on the account

 Create the user through the Partner API. The email address is the username.

 Token sign-in is rejected

 The `email` parameter does not match a user on the account exactly

 Use the same email address as the user created through the Partner API.

 Token sign-in is rejected

 The `wl` parameter does not match `whiteLabel.wl_partners`, or the `whiteLabel` feature is not active on the account

 Add `whiteLabel` with your partner alias to the account's `appFeatures`.

 Token sign-in is rejected

 The `account` parameter is not the account's `accountRegNo`, or the parameter values are not URL-encoded

 Send the `accountRegNo` and URL-encode all values, in particular the email address.

 Token sign-in is rejected on an account that uses single sign-on

 The account is set up for single sign-on through Qvalia, which always takes precedence

 Use either token login or single sign-on on the account, not both.

 A saved or bookmarked login link stops working

 The token in the link is short-lived by design

 Start the hand-off from your application again. Your backend should issue a new token for every hand-off.

 Token sign-in fails after a key change

 Qvalia does not have your new public key yet

 Send the new public key to Qvalia before you switch, so both keys are valid during the change.

### Partner API and data in the portal

 Symptom

 Cause

 What to do

 You cannot manage an account through the API

 API integration is not active on the account

 Activate `apiIntegration` in the account's `appFeatures`.

 The API returns `429`

 The rate limit for the account has been reached

 Wait the number of seconds in `Retry-After` before retrying.

 Invoices created in the portal show the wrong bank account

 Another bank account is marked `is_default`

 Mark the right bank account as default. Only one default is allowed.

 Fields disappear from a Peppol identifier after an update

 Peppol identifiers are updated with a full-object `PUT`

 Read the current object first, then send the complete changed version.

 A user who has left can still sign in

 The user has not been removed from the account

 Remove the user through the Partner API, and keep users in sync with your own system.

### If it still does not work

- Check each record and parameter one last time against [How to set up domains and DNS](https://knowledge.qvalia.com/white-label-domains-and-dns?hsLang=en) and [How to choose a sign-in method](https://knowledge.qvalia.com/white-label-sign-in-methods?hsLang=en).
- Have your partner alias, the environment (test or production), the hostname, the `accountRegNo`, the user's email address, the time of the attempt and any `type` code from the API ready. Never send tokens, API keys or private keys.
- Contact your Qvalia partner manager, or reach Qvalia Support via [qvalia.com/contact-support](https://qvalia.com/contact-support).

- [General](https://knowledge.qvalia.com/general?hsLang=en#main-content)

    - [Peppol](https://knowledge.qvalia.com/general?hsLang=en#peppol)
- [Partner](https://knowledge.qvalia.com/partner?hsLang=en)
- [Logs and monitoring](https://knowledge.qvalia.com/logs-and-monitoring?hsLang=en)
- [Integrations](https://knowledge.qvalia.com/integrations?hsLang=en)
- [Invoice management](https://knowledge.qvalia.com/invoice-management?hsLang=en)
- [Order management](https://knowledge.qvalia.com/order-management?hsLang=en)
- [Data management](https://knowledge.qvalia.com/data-management?hsLang=en)
- [Security and compliance](https://knowledge.qvalia.com/security-and-compliance?hsLang=en)
- [Account](https://knowledge.qvalia.com/account?hsLang=en)
- [Troubleshooting](https://knowledge.qvalia.com/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.qvalia.com/hs-fs/hubfs/Qvalia%20Logo%20New%20Blue%20transparent.png?width=107&height=24&name=Qvalia%20Logo%20New%20Blue%20transparent.png "Chill listening crop-3")](https://qvalia.com/)

Knowledge base

Copyright © 2025, Qvalia