Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Administration
  3. Guides
  4. SAML(SSO)

Pulumi Cloud SAML(SSO)

    The Pulumi Cloud can be configured to work with any SAML 2.0 identity provider. SAML is one of the identity providers that can back a Pulumi organization’s membership; these guides cover configuring it once you have selected it.

    Running self-hosted Pulumi Cloud? You’ll first need to configure your self-hosted infrastructure for SAML SSO (API service keys and environment variables), then return here to complete IdP configuration.

    Single Sign-On (SSO)

    If you’re a member of a SAML-based Pulumi organization, you can sign in to your account via Single Sign-On. To learn about the important aspects of configuring SSO for your IdP, refer to the SSO page.

    Pulumi supports only one Pulumi Cloud organization per SCIM application. If your team manages multiple Pulumi Cloud organizations, you must configure separate SCIM applications for each Pulumi Cloud organization in your Identity Provider.

    Signing in through SSO without an existing Pulumi account creates one, and the organization manages that account: it can’t join unrelated organizations, connect other identity providers, or create organizations of its own. An account that already existed and later connects a SAML identity keeps those abilities. See Organization-managed users.

    Connect SAML SSO to an existing account

    If you already have a Pulumi account and need to access a SAML-based organization, connect that organization’s SAML SSO identity to your existing account rather than signing in to the organization directly. Signing in directly can produce an “Email already in use” error when your email already belongs to an account, and that screen cannot resolve the conflict on its own.

    To connect a SAML SSO identity to your existing account:

    1. Sign in to Pulumi Cloud with your existing account.
    2. Navigate to Account Settings > Connect SAML SSO.
    3. Enter the name of the organization you want to access, then complete the single sign-on prompt with your identity provider.

    After your identity provider confirms your identity, Pulumi adds the organization’s SAML identity to your existing account and grants you access to the organization.

    If the connection fails, confirm with your organization administrator that your identity provider assigns you to the Pulumi application for that organization and that the SAML NameID it sends is stable. An unstable NameID can create duplicate identities and repeat the conflict.

    Before you configure SAML

    The admin who makes this change can’t belong to other, unrelated Pulumi organizations. Pulumi rejects the switch to SAML otherwise, and the error surfaces at the last step of setup. Either have an admin who belongs only to this organization make the change, or leave the other organizations first.

    Switching an organization to SAML is reversible, but not cleanly. Selecting a different identity provider later discards the organization’s SAML identities, its SAML member roster, and its SCIM access token. See Removing a third-party identity provider.

    Integration Guides

    If you’re looking to integrate Pulumi with your SAML 2.0 identity provider, refer to one of our example guides:

      The infrastructure as code platform for any cloud.