Back to Blog
Blog

SAML SSO: Sign In Through Your Identity Provider

Cosmic's avatar

Cosmic

September 10, 2026

Hero image

Workspace admins on Large Workspace and Enterprise can now enable SAML single sign-on. The team signs in through Okta, Entra ID, Google Workspace, or any SAML 2.0 identity provider, from Login with Continue with SSO.

cosmic-login.png

What's New

  • Included on Large Workspace and Enterprise. SSO is part of the plan, not an add-on. Small Workspace and project plans do not include it.

  • One SAML connection per workspace. A workspace admin enables it under Settings, copies the ACS URL and Entity ID to the identity provider, and pastes the IdP metadata URL back. The connection stays pending until metadata is saved.

  • Continue with SSO on the login page. Enter the workspace slug, complete sign-in at the identity provider, and Cosmic opens that workspace.

  • Password and social login are blocked for members. Once SSO is enabled, password, Google, GitHub, and forgot password stop working for the team. The login page tells them to use Continue with SSO.

  • Breakglass for the people who set it up. The workspace creator and the admin who enabled SSO can still use password login if the identity provider is down.

  • First login creates the Cosmic account if needed. An existing email match keeps the role they already have. A new SSO login lands as a Workspace User. Invite them first if they should land as Admin or Manager.

Why This Matters

Who can open Cosmic should be decided in one place: your identity provider. Without SSO, each person holds a Cosmic password, or a Google or GitHub account, that IT cannot see or revoke. That is a second roster, and it drifts.

SSO puts Cosmic behind the same policy you already run. MFA, session rules, and offboarding happen at the IdP. When someone is revoked there, they cannot complete a new Cosmic login. Workspace admins still assign Cosmic roles. They no longer have to be the ones who decide whether that person is allowed in.

How It Works

  1. Open the workspace and go to Settings. Enable SAML SSO.

  2. Send the ACS URL and Entity ID to your identity provider. Paste their metadata URL back into Cosmic and save.

  3. When the connection is active, tell the team to sign in from Login with Continue with SSO and the workspace slug.

Enabling SSO starts the password lock for members, even while the connection is still pending. Finish the identity provider setup before the team needs to sign in again.

Note: Do not reuse a callback URL. Each attempt issues a one-time token. Always start from Login.

When Someone Leaves

Revoke them at the identity provider so they cannot complete a new SSO login. Then remove them from Workspace > Team. Doing only one of those is not enough: an IdP-only revoke leaves the Cosmic team row, and a Cosmic-only remove lets the next SSO login add them back as a Workspace User.

Existing sessions stay up until they expire. The lock applies on the next login.

What It Doesn't Cover

  • SCIM directory sync is not included yet. Roster changes in the identity provider do not automatically create or remove Cosmic team members.

  • OIDC is not offered in this release. SAML 2.0 only.

  • Enabling SSO does not email the team. Tell them before you turn it on: existing sessions stay up, the next password or Google or GitHub login fails, and they need the workspace slug.

Get Started

Give your AI agents a content backend they can write to

Structured, versioned content objects, a REST API and TypeScript SDK, and an MCP server your coding agent connects to directly. The Free plan includes 1 Bucket, 1,000 Objects, and 1 agent. No credit card required.

Hero image