It's easy to include the #/ ending on the sso url (i.e. https://MYORG.awsapps.com/start#/) when configuring sso in aws, and it's not clear from any error message what's wrong (you'll get "Current cached SSO login is expired or invalid"). Perhaps we could allow for this difference?