Skip to main content
Single sign-on (SSO) lets your team sign in to CostGraph with your company identity provider. You verify the email domains you own, connect one identity provider, and choose whether people from those domains join automatically and whether SSO is required. Organization owners set up SSO under Settings > Single sign-on. The page has three sections: Domains, Identity provider, and Require single sign-on.

Verify a domain

You prove you own a domain by adding a DNS record. Only people with an email address at a verified domain can sign in through your identity provider.
1

Add the domain

Under Domains, enter the domain, such as example.com, and click Add domain.
2

Create the TXT record

CostGraph shows a TXT record Name and Value. Copy the value now, because it’s shown only once. At your DNS provider, create a TXT record with that name and value.
3

Verify

Click Verify now. DNS changes can take a while to spread; if it doesn’t verify straight away, try again later.
A domain shows one of these statuses: Keep the TXT record in place after verification. CostGraph checks it daily.

Connect your identity provider

Choose SAML for Okta, Microsoft Entra ID, or Google Workspace, or OpenID Connect for another OIDC provider. You can’t switch protocol later without removing the identity provider. For SAML, add CostGraph as an app in your identity provider first, then give CostGraph its metadata, as a Metadata URL or by uploading the metadata file. CostGraph needs your provider to send the user’s email address in the attribute named:
After you save, CostGraph lists the values your identity provider needs under Enter these values in your identity provider. SAML uses the Entity ID (audience) and ACS URL (reply URL). OpenID Connect uses the Redirect URI. Copy them from the page; they’re specific to CostGraph’s sign-in service, not to your organization. Sign-in must start from CostGraph. Opening the app from your identity provider’s dashboard isn’t supported.
  1. In the Okta admin console, go to Applications > Applications and click Create App Integration. Select SAML 2.0.
  2. Name the app CostGraph. For Single sign-on URL, enter the ACS URL from CostGraph. For Audience URI (SP Entity ID), enter the Entity ID.
  3. Under Attribute Statements, add an attribute named http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress with the value user.email.
  4. To map groups to roles, under Group Attribute Statements, add an attribute named groups with a filter that matches the groups to send.
  5. Finish the app, assign people or groups to it, and copy the Metadata URL from the Sign On tab into CostGraph.
People sign in by entering their work email on the CostGraph sign-in page. CostGraph sends them to your identity provider.

Roles from groups

Set a Default role for people who sign in through SSO. To map groups to roles, click Map a group, then enter the group name your identity provider sends and the CostGraph role it grants. Groups attribute is the name of the attribute that carries the groups, such as groups. You can grant Member, Admin, or Billing admin this way. CostGraph applies the role every time the person signs in. When several groups match, the highest role wins, in the order Admin, Billing admin, Member. People in no mapped group get the default role. Organization owners keep their role.

Auto-join

Turn on Auto-join for a verified domain to let anyone with an email address at that domain join your organization without an invitation. People who join this way get the Member role. Auto-join is off by default.

Require single sign-on

Turn on Require single sign-on to make your identity provider the only way in. You need a verified domain and an identity provider first. When you turn it on:
  • Everyone’s current sessions and app authorizations end, and they sign in again through SSO.
  • You choose what happens to personal API keys: Keep personal API keys or Revoke personal API keys. Keys for agents and installs keep working.
Organization owners can still sign in with a password and an authenticator app, so you can get in if your identity provider is down. Set up an authenticator app under your account’s Security settings before you turn on enforcement.

Self-hosted

Self-hosted deployments sign in with email and password or Google. SAML and OpenID Connect aren’t available on self-hosted deployments yet.