Skip to main content
Single sign-on lets your team sign in to CloudThinker with your existing identity provider — no separate passwords, with accounts created automatically and access removed centrally when someone leaves. SSO is available on Scale, Scale+, and Enterprise plans.
SSO is configured by the organization Owner in Admin Settings → Identity and access.

How setup works

The Identity and access page walks you through three stages:
  1. Verify a domain — prove ownership of your email domain with a DNS TXT record. The Setup SSO button stays disabled until at least one domain is verified.
  2. Create the connection — a wizard with steps Protocol → SP Metadata → IdP Config (SAML) or Protocol → IdP Config (OIDC).
  3. Configure provisioning — once the connection is active, choose how users are created and which role and workspaces they get.

Verify your domain

1

Add your email domain

Go to Admin Settings → Identity and access and add your organization’s email domain (for example, example.com).
2

Create the DNS TXT record

Open Verify domain on the domain entry. Add a TXT record at your DNS provider using the Record Name (Host) and Record Value shown.
3

Verify

After the record propagates, click Verify.Success state: the domain shows as verified and the Setup SSO button on the Single sign-on card becomes available.

Create the connection

Click Setup SSO on the Single sign-on card and choose your protocol, then follow the provider-by-provider guide: After you click Create Connection, use Test on the connection to confirm authentication round-trips before anyone depends on it: a browser tab opens, signs in through your identity provider, and returns to CloudThinker with your name and email.

Enforce SSO

Once the connection is active and tested, you can require it. On the Single sign-on card, turn on Require SSO — users must then authenticate via SSO, and all other login methods are disabled.
Confirm at least one Owner account signs in successfully through SSO before turning on Require SSO. If your identity provider breaks after enforcement, an Owner needs a working SSO session to turn it back off.

User provisioning

When the connection is active, the provisioning card offers three modes: For Just-in-time and SCIM, you also choose the auto-assigned organization role (Viewer, Developer, or Admin — the default is Viewer) and the workspaces new users are added to.

Troubleshooting

At least one email domain must be verified first. Check the domain entry’s verification status and confirm your DNS TXT record matches the Record Name (Host) and Record Value shown in the Verify domain dialog. DNS changes can take time to propagate.
Open the provider-specific attribute mapping table in the SAML or OIDC guide and confirm your identity provider sends email, firstName, and lastName.
Confirm the CloudThinker app is assigned to the affected users in your identity provider. An Owner with a working SSO session can turn off Require SSO on the Single sign-on card.
Require SSO applies to users whose email is on a verified domain. Check that the user’s email domain is verified and enforcement is on.

Next steps

SAML Setup

Provider-by-provider SAML configuration steps

OIDC Setup

Provider-by-provider OIDC configuration steps

SCIM Provisioning

Automate user and group sync from your identity provider

Security Overview

MFA, roles and permissions, and audit logs