Before you begin
- You must be an owner of the CostGraph organization.
- Set up single sign-on for your organization first if you want groups to map to roles. The group to role mapping lives in your single sign-on settings.
- Make sure each person’s username in your identity provider is their email address.
Create a provisioning token
- In CostGraph, go to Settings > Organization > Single sign-on.
- In the Provisioning (SCIM) card, click Create token. CostGraph shows the SCIM base URL and the token.
- Copy the token now. CostGraph shows it a single time.
https://api.costgraph.ai/scim/v2.
The card also shows when your identity provider last synced. To replace the token, click Rotate token. The old token stops working immediately, so update your identity provider right away. To stop provisioning, click Revoke token.
Connect Okta
1
Turn on SCIM
In the Okta Admin Console, open your CostGraph app integration. On the General tab, click Edit under App Settings, set Provisioning to SCIM, and save.
2
Configure the connector
On the Provisioning tab, select Integration and click Edit. Enter these values:
- SCIM connector base URL:
https://api.costgraph.ai/scim/v2 - Unique identifier field for users:
userName - Supported provisioning actions: Push New Users, Push Profile Updates, and Push Groups
- Authentication Mode: HTTP Header, with the provisioning token as the Bearer token
3
Test and save
Click Test Connector Configuration, then click Save after the test passes.
4
Choose what Okta changes
Under Provisioning > To App, click Edit and enable Create Users, Update User Attributes, and Deactivate Users.
5
Assign people and push groups
On the Assignments tab, assign the people and groups who need CostGraph. On the Push Groups tab, push the groups you map to roles.
Connect Microsoft Entra ID
1
Open provisioning
In the Microsoft Entra admin center, go to Enterprise applications, open your CostGraph app, and select Provisioning. Set Provisioning Mode to Automatic.
2
Enter the credentials
Under Admin Credentials, set Tenant URL to
https://api.costgraph.ai/scim/v2 and Secret Token to the provisioning token. Click Test Connection.3
Check the mappings
Under Mappings, open the user mapping. Map
userName to userPrincipalName if your user principal names are email addresses. Otherwise map it to mail. Keep the active mapping.4
Set the scope and start
Under Settings, set Scope to Sync only assigned users and groups. Assign people and groups to the app, then click Start provisioning.
Members
CostGraph uses the username as the member’s email address. A username that isn’t an email address is refused, as are addresses on domains reserved for CostGraph staff. A new member gets the default role from your single sign-on settings, or Member if you haven’t set one. New members don’t get workspace access automatically, the same as members who join through single sign-on. An admin grants workspace access in CostGraph.Deactivation
When you deactivate or unassign someone in your identity provider, CostGraph immediately:- Deactivates their membership in your organization.
- Disconnects the apps they signed in to with their CostGraph account.
- Disables their personal API keys.
Groups and roles
CostGraph maps pushed groups to roles with the group to role mapping in your single sign-on settings. When someone is in several mapped groups, the highest role wins: Admin, then Billing admin, then Member. Someone in no mapped group gets the default role. Provisioning doesn’t make anyone an owner or change an owner’s role. It can deactivate an owner, but not the last active owner.Supported requests
CostGraph supports theUsers and Groups resources. You can filter users by userName or externalId and groups by displayName or externalId, with the eq operator.
Requests are rate limited per organization. When you go over the limit, CostGraph answers 429 with a Retry-After header, and Okta and Microsoft Entra ID retry on their own.
The audit log records every provisioning action.