Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Administration
  3. Access & Identity
  4. SAML(SSO)

Pulumi Cloud SAML(SSO)

    The Pulumi Cloud can be configured to work with any SAML 2.0 identity provider. SAML support requires Pulumi Enterprise or Pulumi Business Critical. To learn more about the capabilities of Pulumi Enterprise or Pulumi Business Critical, refer to the pricing page.

    Running self-hosted Pulumi Cloud? You’ll first need to configure your self-hosted infrastructure for SAML SSO (API service keys and environment variables), then return here to complete IdP configuration.

    Single Sign-On (SSO)

    If you’re a member of a SAML-based Pulumi organization, you can sign in to your account via Single Sign-On. To learn about the important aspects of configuring SSO for your IdP, refer to the SSO page.

    Pulumi supports only one Pulumi organization per SCIM application. If your team manages multiple Pulumi organizations, you must configure separate SCIM applications for each organization in your Identity Provider.

    Connect SAML SSO to an existing account

    If you already have a Pulumi account and need to access a SAML-based organization, connect that organization’s SAML SSO identity to your existing account rather than signing in to the organization directly. Signing in directly can produce an “Email already in use” error when your email already belongs to an account, and that screen cannot resolve the conflict on its own.

    To connect a SAML SSO identity to your existing account:

    1. Sign in to Pulumi Cloud with your existing account.
    2. Navigate to Account Settings > Connect SAML SSO.
    3. Enter the name of the organization you want to access, then complete the single sign-on prompt with your identity provider.

    After your identity provider confirms your identity, Pulumi adds the organization’s SAML identity to your existing account and grants you access to the organization.

    If the connection fails, confirm with your organization administrator that your identity provider assigns you to the Pulumi application for that organization and that the SAML NameID it sends is stable. An unstable NameID can create duplicate identities and repeat the conflict.

    Integration Guides

    If you’re looking to integrate Pulumi with your SAML 2.0 identity provider, refer to one of our example guides:

      The infrastructure as code platform for any cloud.