Verify a domain
You prove you own a domain by adding a DNS record. Only people with an email address at a verified domain can sign in through your identity provider.1
Add the domain
Under Domains, enter the domain, such as
example.com, and click Add
domain.2
Create the TXT record
CostGraph shows a TXT record Name and Value. Copy the value now,
because it’s shown only once. At your DNS provider, create a TXT record
with that name and value.
3
Verify
Click Verify now. DNS changes can take a while to spread; if it
doesn’t verify straight away, try again later.
Keep the TXT record in place after verification. CostGraph checks it daily.
Connect your identity provider
Choose SAML for Okta, Microsoft Entra ID, or Google Workspace, or OpenID Connect for another OIDC provider. You can’t switch protocol later without removing the identity provider. For SAML, add CostGraph as an app in your identity provider first, then give CostGraph its metadata, as a Metadata URL or by uploading the metadata file. CostGraph needs your provider to send the user’s email address in the attribute named:- Okta
- Microsoft Entra ID
- Google Workspace
- OpenID Connect
- In the Okta admin console, go to Applications > Applications and click Create App Integration. Select SAML 2.0.
- Name the app
CostGraph. For Single sign-on URL, enter the ACS URL from CostGraph. For Audience URI (SP Entity ID), enter the Entity ID. - Under Attribute Statements, add an attribute named
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddresswith the valueuser.email. - To map groups to roles, under Group Attribute Statements, add an
attribute named
groupswith a filter that matches the groups to send. - Finish the app, assign people or groups to it, and copy the Metadata URL from the Sign On tab into CostGraph.
Roles from groups
Set a Default role for people who sign in through SSO. To map groups to roles, click Map a group, then enter the group name your identity provider sends and the CostGraph role it grants. Groups attribute is the name of the attribute that carries the groups, such asgroups.
You can grant Member, Admin, or Billing admin this way. CostGraph
applies the role every time the person signs in. When several groups match,
the highest role wins, in the order Admin, Billing admin, Member. People in no
mapped group get the default role. Organization owners keep their role.
Auto-join
Turn on Auto-join for a verified domain to let anyone with an email address at that domain join your organization without an invitation. People who join this way get the Member role. Auto-join is off by default.Require single sign-on
Turn on Require single sign-on to make your identity provider the only way in. You need a verified domain and an identity provider first. When you turn it on:- Everyone’s current sessions and app authorizations end, and they sign in again through SSO.
- You choose what happens to personal API keys: Keep personal API keys or Revoke personal API keys. Keys for agents and installs keep working.