Single sign-on (SSO)

SAML-based SSO for enterprise workspaces.

Last updated

SSO is available on the Enterprise plan. It lets your team sign in to Cocobox with the same identity provider they use for everything else — Okta, Azure Entra, Google Workspace, JumpCloud, OneLogin, or any SAML 2.0 IdP.

What you get

  • SAML 2.0 sign-in.
  • JIT provisioning — first-time sign-in creates the Cocobox user automatically with default member role.
  • SCIM 2.0 (optional) — automatic user lifecycle: create, update, deactivate.
  • Domain capture — anyone signing up with @yourcompany.com is forced through SSO.
  • Group → role mapping — IdP groups can be mapped to Cocobox workspace roles.

Set it up

Settings → Workspace → SSO (visible only on Enterprise).

  1. Pick your IdP from the list (or “Generic SAML”).
  2. Cocobox shows the SP metadata: Entity ID, ACS URL, SLO URL.
  3. In your IdP, create a new app, paste those values.
  4. Your IdP returns its metadata XML or URL — paste it into Cocobox.
  5. Test the sign-in flow with a single user.
  6. Enable Required to force all members to use SSO.

SCIM

After SSO is live, scroll to SCIM → generate a token. Configure in your IdP. Cocobox supports the standard Users and Groups endpoints. Deactivating a user in the IdP removes their access from Cocobox within minutes.

Group → role mapping

Map IdP groups to Cocobox workspace roles. Members of the IdP group cocobox-admins automatically get the workspace admin role; members of cocobox-engineers get member. Members of unmapped groups default to guest.

You can also map IdP groups to connection roles — eng-prod-readonly could map to read on the prod connection. Useful when you want IdP to be the source of truth for database access.

Break-glass

When SSO breaks (misconfigured IdP, certificate expired), you can still get in:

  • The original workspace owner can sign in with email/password as a fallback.
  • Cocobox provides a one-time break-glass URL to enterprise customers, rotatable, used when even the owner is locked out.

Status

If you’re not yet on Enterprise but need SSO, contact sales@cocobox.io. We’ll demo and quote.