SSO
Overview
SAML 2.0 SSO is available at no additional cost on Teams and Enterprise plans. Use your existing identity provider (IdP) to authenticate team members without separate Cursor accounts.
This page covers team-level SSO in Team Settings. Use it on a Teams plan, or on a team that still has its own identity provider. Enterprise org admins configure SSO in the Organization's Settings. See Organizations and Identity and access management.
Prerequisites
- Cursor Teams plan, or a team that still uses team-level SSO
- Admin access to your identity provider (e.g., Okta)
- Admin access to your Cursor team
Configuration Steps
Sign in to your Cursor account
Navigate to the Single Sign-On (SSO) settings with a team admin account.
Locate the SSO configuration
Find the "Single Sign-On (SSO)" section and expand it.
Begin the setup process
Click "Configure" next to "SSO-Provider Connection Settings" to start SSO setup and follow the wizard.
Configure your identity provider
In your identity provider (e.g., Okta):
- Create new SAML application
- Configure SAML settings using Cursor's information
- Set up Just-in-Time (JIT) provisioning
Verify domain
Click "Configure" next to "Domain Verification Settings" to verify your users' domain.
View your SSO configuration
Team admins can review a team-level SSO connection and its domains at any time:
- Go to Single Sign-On (SSO) settings with a team admin account.
- Click "Configure" next to "SSO-Provider Connection Settings" to view the provider connection details.
- Click "Configure" next to "Domain Verification Settings" to view or manage verified domains.
These settings are for team-level SSO. Enterprise org admins review org-level SSO in the Organization's Settings. See Organizations.
Identity Provider Setup Guides
For provider-specific setup instructions:
Identity Provider Guides
Setup instructions for Okta, Azure AD, Google Workspace, and more.
Additional Settings
Once domain verification and the SSO provider connection are active, users on that domain are required to sign in with SSO. There is no separate enforcement toggle.
- New users auto-enroll when signing in through SSO
- Handle user management through your identity provider
Multiple domains
To handle multiple domains in your organization:
- Verify each domain separately in Cursor through the domain verification settings
- Configure each domain in your identity provider
- Each domain needs to go through the verification process independently
Troubleshooting
User is not assigned to this application
If Microsoft Entra ID returns AADSTS50105, or another identity provider returns User is not assigned to this application, Cursor cannot grant access. The identity provider is blocking sign-in because the user is not assigned to the Cursor enterprise app.
Ask an admin in your identity provider to assign the user directly, or as a direct member of an assigned group. Nested groups often fail: membership in a group that sits under an assigned group is not enough on many providers, including Microsoft Entra ID.
After the assignment is saved, wait a few minutes for it to propagate, then have the user sign in again.
See SSO and authentication for the member-facing version of this error.
Other issues
- Verify the domain is verified in Cursor
- Ensure SAML attributes are properly mapped
- Confirm the SSO connection is active and the domain is verified
- Match first and last names between identity provider and Cursor
- Check provider-specific guides above
- Visit the SSO help center if issues persist