Single sign-on (SSO)
SAML-based SSO for enterprise workspaces.
SSO is available on the Enterprise plan. It lets your team sign in to Cocobox with the same identity provider they use for everything else — Okta, Azure Entra, Google Workspace, JumpCloud, OneLogin, or any SAML 2.0 IdP.
What you get
- SAML 2.0 sign-in.
- JIT provisioning — first-time sign-in creates the Cocobox user automatically with default
memberrole. - SCIM 2.0 (optional) — automatic user lifecycle: create, update, deactivate.
- Domain capture — anyone signing up with
@yourcompany.comis forced through SSO. - Group → role mapping — IdP groups can be mapped to Cocobox workspace roles.
Set it up
Settings → Workspace → SSO (visible only on Enterprise).
- Pick your IdP from the list (or “Generic SAML”).
- Cocobox shows the SP metadata: Entity ID, ACS URL, SLO URL.
- In your IdP, create a new app, paste those values.
- Your IdP returns its metadata XML or URL — paste it into Cocobox.
- Test the sign-in flow with a single user.
- Enable Required to force all members to use SSO.
SCIM
After SSO is live, scroll to SCIM → generate a token. Configure in your IdP. Cocobox supports the standard Users and Groups endpoints. Deactivating a user in the IdP removes their access from Cocobox within minutes.
Group → role mapping
Map IdP groups to Cocobox workspace roles. Members of the IdP group cocobox-admins automatically get the workspace admin role; members of cocobox-engineers get member. Members of unmapped groups default to guest.
You can also map IdP groups to connection roles — eng-prod-readonly could map to read on the prod connection. Useful when you want IdP to be the source of truth for database access.
Break-glass
When SSO breaks (misconfigured IdP, certificate expired), you can still get in:
- The original workspace owner can sign in with email/password as a fallback.
- Cocobox provides a one-time break-glass URL to enterprise customers, rotatable, used when even the owner is locked out.
Status
If you’re not yet on Enterprise but need SSO, contact sales@cocobox.io. We’ll demo and quote.