Single sign-on

SAML single sign-on lets your team sign in to Cosmic through your identity provider. It is included on Large Workspace and Enterprise. SCIM directory sync is not available yet.

Who can enable it

A Workspace Admin enables SSO from Workspace Settings. The workspace must be on the Large Workspace or Enterprise plan.

Project plans (Free, Builder, Team, Business) and Small Workspace do not include SSO.

Set up SAML

  1. In Cosmic, go to Workspace Settings and click Enable SAML SSO.
  2. Copy the ACS URL and Entity ID Cosmic shows you.
  3. In your identity provider (Okta, Entra ID, Google Workspace, or any SAML 2.0 IdP), create a SAML application and set both values as the assertion consumer URL and audience.
  4. Copy the identity provider metadata URL and paste it into Cosmic under IdP metadata URL, then save.

The connection stays pending until metadata is saved. When Cosmic shows the connection as active, the team can sign in with SSO.

Sign in

  1. Open Login and click Continue with SSO.
  2. Enter the workspace slug (the slug in Workspace Settings, not the Cosmic organization id).
  3. Complete sign-in at your identity provider.

After a successful sign-in, Cosmic opens that workspace.

Do not reuse a callback URL. Each SSO attempt issues a one-time token. Always start from Login.

First login and roles

The first time someone signs in with SSO, Cosmic creates their account if needed and adds them to the workspace as a Workspace User. Invite them to Cosmic first if they should land with a different role. An existing email match keeps the role they already have.

They still need a Project and Bucket role to work on content. See Roles and permissions.

Password and social login

Once SSO is enabled, members of that workspace cannot use password, Google, GitHub, or forgot password. The login page tells them to use Continue with SSO.

The workspace creator, and the admin who enabled SSO, can still use password login so you are not locked out if the identity provider is down.

When someone leaves

Revoke them at the identity provider so they cannot complete a new SSO login. Then remove them from Workspace > Team so they disappear from the Cosmic roster.

Removing them only in the identity provider does not remove the Cosmic team row. Removing them only in Cosmic does not stop a later SSO login from adding them back as a Workspace User. Do both.

SCIM would keep the two sides in sync. It is not included yet.

Disable SSO

Workspace Admins can disable SSO from the same settings panel. Password and social login work again for members after it is turned off.