Self-serve setup
Your CodeRabbit account team prepares your organization and invites an organization admin to the account management page. From there, the admin opens Security, verifies the email domain, configures the SAML application, tests the connection, and activates SSO. Every provider follows the same wizard stages:- Open the wizard from Security > Start configuration.
- Add and verify your email domain.
- Select your identity provider and create the SAML application.
- Map SAML attributes and assign the users or groups that should sign in.
- Add your identity provider metadata, test the connection, and activate SSO.
Available guides
Okta SAML
Configure Okta SAML through the self-serve account management flow, verify your domain, test the connection, and activate Enterprise SSO.
Google Workspace SAML
Configure Google Workspace SAML through the self-serve account management flow, create a custom SAML app, test the connection, and activate Enterprise SSO.
Microsoft Entra ID SAML
Configure Microsoft Entra ID SAML through the self-serve account management flow, create an Enterprise application, test the connection, and activate Enterprise SSO.
Custom SAML
Configure a custom SAML identity provider through the self-serve account management flow, map attributes, test the connection, and activate Enterprise SSO.
SCIM directory sync
Sync assigned users from your identity provider into CodeRabbit after SAML SSO is enabled for your workspace.
Workspace roles
Enterprise SSO workspaces add a workspace role layer on top of standard organization roles. A user can hold a workspace role that applies across the entire SSO workspace and an organization role for a specific organization inside it. When a workspace role exists, CodeRabbit applies it first for workspace-level surfaces such as Workspace Team Management. Use Workspace Team Management to assign workspace roles and organization roles from the same member list. Organization-role editing applies to one selected organization at a time: choose the organization, then update each member’s role for that organization from the member list. Members who have a workspace seat but do not belong to the selected organization remain visible and show Not in this org instead of an editable organization-role control. Workspace admins can also manage the workspace seat assignment mode from Workspace Team Management. Automatic mode assigns members a seat when they open a pull request, while Manual mode lets admins assign seats individually. Billing Admin roles remain protected and cannot be changed from the role selector. Billing admins cannot be assigned a seat that consumes a license through Workspace Team Management. If a billing admin already has a seat, admins can still unassign it to free the license. Member users in SSO workspaces do not receive default access to Subscription and Billing, billing controls, or Team Management unless their workspace role or a custom role explicitly grants the corresponding permission.CodeRabbit configuration
Enterprise SSO workspaces include a Workspace configuration page in the CodeRabbit UI. Workspace admins can use it to define CodeRabbit configuration that applies as a shared baseline across every organization in the workspace. In CodeRabbit Cloud, self-hosted Git provider organizations linked to a workspace can access the equivalent controls under Workspace Settings. Users who can view Organization Settings can view that workspace configuration, while saving settings or global overrides requires permission to update Organization Settings. Workspace global overrides take precedence over organization global overrides when both levels set the same key. See configuration inheritance for the full priority order.What’s next
SCIM directory sync
Provision and deprovision users automatically from your identity provider after SAML SSO is active.
Roles and permissions
Review how CodeRabbit roles work so you can combine SSO with the right access model for your organization.
Support
Contact the CodeRabbit team if you need your service provider values or help troubleshooting the rollout.