SSO and authentication
SSO with SAML 2.0 is available at no additional cost on Teams and Enterprise plans. Where you configure it depends on whether you use team-level or org-level SSO.
What do I need before setting up SSO?
- A Cursor Teams or Enterprise plan
- Admin access to your identity provider (e.g., Okta, Azure AD, Google Workspace)
- Admin access to your Cursor team (Teams) or organization (Enterprise)
Where do I configure SSO?
- Teams: Open Single Sign-On (SSO) settings in Team Settings.
- Enterprise: Open the Organization's Settings. Org-level SSO is configured there, not in Team Settings. See Organizations.
Team-level SSO stays available for a team that needs its own identity provider. Most Enterprise orgs should use org-level SSO.
How do I set up SSO?
For team-level SSO, follow the SSO setup reference. You'll need admin access to both your identity provider and your Cursor team.
For org-level SSO on Enterprise, set up the connection in the Organization's Settings. See Organizations and Identity and access management.
Does Cursor support SCIM provisioning?
Yes, on Enterprise plans with SSO enabled. SCIM automatically manages team members through your identity provider, keeping your Cursor team in sync with your organization.
How do I view my SSO configuration and domains?
For team-level SSO, team admins can review the connection status and its domain in Single Sign-On (SSO) settings. Click "Configure" next to "SSO-Provider Connection Settings" to view the provider connection details. Click "Configure" next to "Domain Verification Settings" to view or manage verified domains.
For org-level SSO, org admins review the connection in the Organization's Settings. See Organizations.
Why do I see AADSTS50105 or "User is not assigned to this application"?
Your identity provider blocked the sign-in. The Cursor enterprise app requires assignment, and you are not assigned to it. Cursor cannot add you.
Ask your IT admin to assign you to the Cursor app as a user, or as a direct member of an assigned group. Nested groups often fail on Microsoft Entra ID and similar providers. Being in a group nested under an assigned group is not enough.
After they assign you, wait a few minutes for the change to propagate, then sign in again.
See SSO troubleshooting for the admin version of these steps.