Pulumi Cloud SAML(SSO)
The Pulumi Cloud can be configured to work with any SAML 2.0 identity provider. SAML is one of the identity providers that can back a Pulumi organization’s membership; these guides cover configuring it once you have selected it.
Single Sign-On (SSO)
If you’re a member of a SAML-based Pulumi organization, you can sign in to your account via Single Sign-On. To learn about the important aspects of configuring SSO for your IdP, refer to the SSO page.
Signing in through SSO without an existing Pulumi account creates one, and the organization manages that account: it can’t join unrelated organizations, connect other identity providers, or create organizations of its own. An account that already existed and later connects a SAML identity keeps those abilities. See Organization-managed users.
Connect SAML SSO to an existing account
If you already have a Pulumi account and need to access a SAML-based organization, connect that organization’s SAML SSO identity to your existing account rather than signing in to the organization directly. Signing in directly can produce an “Email already in use” error when your email already belongs to an account, and that screen cannot resolve the conflict on its own.
To connect a SAML SSO identity to your existing account:
- Sign in to Pulumi Cloud with your existing account.
- Navigate to Account Settings > Connect SAML SSO.
- Enter the name of the organization you want to access, then complete the single sign-on prompt with your identity provider.
After your identity provider confirms your identity, Pulumi adds the organization’s SAML identity to your existing account and grants you access to the organization.
If the connection fails, confirm with your organization administrator that your identity provider assigns you to the Pulumi application for that organization and that the SAML NameID it sends is stable. An unstable NameID can create duplicate identities and repeat the conflict.
Before you configure SAML
Switching an organization to SAML is reversible, but not cleanly. Selecting a different identity provider later discards the organization’s SAML identities, its SAML member roster, and its SCIM access token. See Removing a third-party identity provider.
Integration Guides
If you’re looking to integrate Pulumi with your SAML 2.0 identity provider, refer to one of our example guides: