> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coderabbit.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise SSO

> Set up Enterprise SSO and SCIM directory sync for your organization.

export const EnterprisePlanBadge = ({tip = "This feature is available exclusively as part of the Enterprise plan. Please refer to our pricing page for more information about our plans and features.", title = "Enterprise Plan", cta = "Read more", href = "https://coderabbit.ai/pricing", disabled = false}) => {
  return <Tooltip tip={tip} cta={cta} href={href}>
        <Badge icon="building-2" disabled={disabled || undefined}>
            {title}
        </Badge>
    </Tooltip>;
};

export const AdminRoleBadge = ({tip = "This feature requires an organization owner, an admin role or the corresponding permission. Regular Members do not have access.", title = "Admin Only", cta = "View roles", href = "/management/roles", disabled = false}) => {
  return <Tooltip tip={tip} cta={cta} href={href}>
        <Badge icon="lock" color="orange" disabled={disabled || undefined}>
            {title}
        </Badge>
    </Tooltip>;
};

<EnterprisePlanBadge />

<AdminRoleBadge tip="This page requires an admin role. Members do not have access to Enterprise SSO settings." />

Enterprise SSO lets your organization manage CodeRabbit access through your existing identity provider and bring multiple Git providers and organizations into one CodeRabbit workspace.

## What Enterprise SSO provides

* **Centralized authentication:** Users sign in through your SAML 2.0 identity provider instead of managing a separate CodeRabbit password.
* **Automated user lifecycle management:** Use [SCIM directory sync](/management/sso/scim) to provision and deprovision workspace members and inherit the Admin role from an identity provider group.
* **A multi-provider workspace:** Connect multiple Git providers, organizations, and self-hosted instances to one workspace.
* **Unified licensing and billing:** Use one workspace subscription and consolidated invoice instead of maintaining a separate subscription for each Git organization.
* **Workspace-wide administration:** Manage roles, seat assignment, review configuration, audit logs, a shared API key, and supported Jira, Linear, and MCP integrations from workspace-level controls.
* **Consistent authentication:** Use the same organization-managed sign-in policy across supported CodeRabbit surfaces, including the web app, IDE extensions, and CLI.

Enterprise SSO is available on the Enterprise plan. Contact your CodeRabbit account team to prepare your organization and designate the first organization admin.

## Supported identity and Git providers

CodeRabbit supports Okta, Microsoft Entra ID, and any SAML 2.0-compliant identity provider.

An Enterprise SSO workspace can include more than one Git provider and more than one instance of a self-hosted provider. Supported providers include:

* GitHub Cloud and GitHub Enterprise Server
* GitLab.com and GitLab Self-Managed
* Bitbucket Cloud and Bitbucket Data Center
* Azure DevOps

## Rollout checklist

Your CodeRabbit account team prepares your organization and invites an organization admin to the account management page. From there, the admin opens **Security**, verifies the email domain, configures the SAML application, tests the connection, and activates SSO.

Plan the rollout in this order:

1. Inventory the email domains, Git providers, Git organizations or groups, and self-hosted instances that should belong to the workspace.
2. Choose at least one organization admin to complete SSO setup and manage the workspace.
3. If you use GitHub Enterprise Server or GitLab Self-Managed, [prepare the existing CodeRabbit OAuth application](/management/sso/self-hosted-git-providers).
4. Accept the CodeRabbit organization invitation and open **Security** > **Start configuration**.
5. Add and verify your email domain.
6. Select your identity provider, create the SAML application, map attributes, and assign the users or groups that should sign in.
7. Add your identity provider metadata, test the connection with an assigned user, and activate SSO.
8. If you use Okta or Microsoft Entra ID, optionally enable [SCIM directory sync](/management/sso/scim) during the SSO rollout for automated member lifecycle management and Admin role mapping.
9. Add the required Git organizations, groups, and providers to the workspace with your CodeRabbit account team.
10. Choose the [workspace seat assignment](/management/seat-assignment#enterprise-sso-workspaces) mode.

For the exact fields, values, and screenshots, follow the [Okta SAML](/management/sso/okta-saml), [Microsoft Entra ID SAML](/management/sso/microsoft-entra-saml), or [SAML 2.0 provider](/management/sso/custom-saml) guide.

<Info>
  SSO authentication, SCIM membership, and PR-review seats are related but separate controls. SSO authenticates IdP members, SCIM manages their workspace membership, and seat assignment determines which Git identities receive paid PR reviews.
</Info>

## Available guides

<CardGroup cols={1}>
  <Card title="Okta SAML" href="/management/sso/okta-saml" icon="folder-key" horizontal>
    Configure Okta SAML through the self-serve account management flow, verify your domain, test the connection, and activate Enterprise SSO.
  </Card>

  <Card title="Microsoft Entra ID SAML" href="/management/sso/microsoft-entra-saml" icon="microsoft" horizontal>
    Configure Microsoft Entra ID SAML through the self-serve account management flow, create an Enterprise application, test the connection, and activate Enterprise SSO.
  </Card>

  <Card title="Any SAML 2.0 provider" href="/management/sso/custom-saml" icon="key" horizontal>
    Configure a SAML 2.0-compliant identity provider through the self-serve account management flow, map attributes, test the connection, and activate Enterprise SSO.
  </Card>

  <Card title="SCIM directory sync" href="/management/sso/scim" icon="users" horizontal>
    Configure Okta or Microsoft Entra ID provisioning during the SSO rollout to manage workspace membership and Admin role inheritance.
  </Card>

  <Card title="Self-hosted Git provider preparation" href="/management/sso/self-hosted-git-providers" icon="server-cog" horizontal>
    Update the CodeRabbit OAuth application before adding GitHub Enterprise Server or GitLab Self-Managed to the SSO workspace.
  </Card>

  <Card title="Seat assignment" href="/management/seat-assignment#enterprise-sso-workspaces" icon="badge-check" horizontal>
    Understand IdP members, Git-only members, identity linking, and seat assignment modes.
  </Card>

  <Card title="SSO user management API" href="/management/sso/user-management-api" icon="users" horizontal>
    Use workspace API tokens to list SSO workspace members, manage seats, and repair linked provider identities.
  </Card>
</CardGroup>

## Workspace roles

Enterprise SSO workspaces add a workspace role layer on top of standard organization roles. A user can hold a workspace role that applies across the entire SSO workspace and an organization role for a specific organization inside it. When a workspace role exists, CodeRabbit applies it first for workspace-level surfaces such as **Workspace Team Management**.

Use **Workspace Team Management** to assign workspace roles and organization roles from the same member list. Organization-role editing applies to one selected organization at a time: choose the organization, then update each member's role for that organization from the member list. Members who have a workspace seat but do not belong to the selected organization remain visible and show **Not in this org** instead of an editable organization-role control.

Workspace admins can also manage the workspace seat assignment mode from **Workspace Team Management**. **Automatic** mode assigns members a seat when they open a pull request, while **Manual** mode lets admins assign seats individually.

Billing Admin roles remain protected and cannot be changed from the role selector. Billing admins cannot be assigned a seat that consumes a license through **Workspace Team Management**. If a billing admin already has a seat, admins can still unassign it to free the license.

Member users in SSO workspaces do not receive default access to Subscription and Billing, billing controls, or Team Management unless their workspace role or a custom role explicitly grants the corresponding permission.

## CodeRabbit configuration

Enterprise SSO workspaces include a **Workspace configuration** page in the CodeRabbit UI. Workspace admins can use it to define CodeRabbit configuration that applies as a shared baseline across every organization in the workspace. In CodeRabbit Cloud, self-hosted Git provider organizations linked to a workspace can access the equivalent controls under **Workspace Settings**. Users who can view Organization Settings can view that workspace configuration, while saving settings or global overrides requires permission to update Organization Settings. Workspace global overrides take precedence over organization global overrides when both levels set the same key.

### Use workspace settings as defaults

<AdminRoleBadge tip="Changing this setting requires a workspace admin role. Other workspace members can view it but cannot change it." />

On **Workspace settings** > **General**, workspace admins can turn on **Use workspace settings as defaults**. This setting is available only to Enterprise SSO workspaces on CodeRabbit Cloud. It is not available to self-hosted or non-SSO organizations, and it is off by default.

When this setting is on, workspace review settings fill values left unset in repository or organization configuration, even when configuration inheritance is off. Explicit repository and organization values and workspace or organization global overrides keep their higher precedence.

The fill follows these rules:

* Missing nested and scalar values are filled from workspace settings.
* An empty array is filled from the corresponding workspace array.
* A non-empty array is not changed.
* Explicit values such as `false`, `0`, or an empty string are not changed.

See [configuration inheritance](/configuration/configuration-inheritance#configuration-hierarchy) for the full priority order.

## What's next

<CardGroup cols={1}>
  <Card title="SCIM directory sync" href="/management/sso/scim" icon="users" horizontal>
    Provision and deprovision users automatically from Okta or Microsoft Entra ID and map an identity provider group to the Admin role.
  </Card>

  <Card title="Seat assignment" href="/management/seat-assignment#enterprise-sso-workspaces" icon="badge-check" horizontal>
    Review how seats are counted and choose Automatic or Manual assignment for the workspace.
  </Card>

  <Card title="Support" href="/support" icon="message-circle" horizontal>
    Contact the CodeRabbit team if you need your service provider values or help troubleshooting the rollout.
  </Card>
</CardGroup>
