Hello,
It might be beneficial to open a case with support as some of the assertion errors provide more detailed messages that we can check on the back end. Some common issues can be,
the audience/recipient in the SAML Assertion does not match what is setup in the SAML IdP in Okta
SAML Assertion is not signed, or algorithm mismatch in Okta SAML IdP setup
if using an Org with a custom domain URL, a possible mismatch in issuer using either the Okta domain or custom domain
sending the SAML Response instead of the Assertion