Skip to main content
Enterprise SSO lets your organization manage CodeRabbit access through your existing identity provider. Use this feature when you want to centralize login for Enterprise users, control access through your identity provider, and roll out sign-in to teams in a managed way.

Self-serve setup

Your CodeRabbit account team prepares your organization and invites an organization admin to the account management page. From there, the admin opens Security, verifies the email domain, configures the SAML application, tests the connection, and activates SSO. Every provider follows the same wizard stages:
  1. Open the wizard from Security > Start configuration.
  2. Add and verify your email domain.
  3. Select your identity provider and create the SAML application.
  4. Map SAML attributes and assign the users or groups that should sign in.
  5. Add your identity provider metadata, test the connection, and activate SSO.
For the exact fields, values, and screenshots, follow the Okta SAML, Google Workspace SAML, Microsoft Entra ID SAML, or Custom SAML guide. After SAML SSO is active, you can optionally enable SCIM directory sync to provision users from your identity provider into CodeRabbit.

Available guides

Okta SAML

Configure Okta SAML through the self-serve account management flow, verify your domain, test the connection, and activate Enterprise SSO.

Google Workspace SAML

Configure Google Workspace SAML through the self-serve account management flow, create a custom SAML app, test the connection, and activate Enterprise SSO.

Microsoft Entra ID SAML

Configure Microsoft Entra ID SAML through the self-serve account management flow, create an Enterprise application, test the connection, and activate Enterprise SSO.

Custom SAML

Configure a custom SAML identity provider through the self-serve account management flow, map attributes, test the connection, and activate Enterprise SSO.

SCIM directory sync

Sync assigned users from your identity provider into CodeRabbit after SAML SSO is enabled for your workspace.

Workspace roles

Enterprise SSO workspaces add a workspace role layer on top of standard organization roles. A user can hold a workspace role that applies across the entire SSO workspace and an organization role for a specific organization inside it. When a workspace role exists, CodeRabbit applies it first for workspace-level surfaces such as Workspace Team Management. Use Workspace Team Management to assign workspace roles and organization roles from the same member list. Organization-role editing applies to one selected organization at a time: choose the organization, then update each member’s role for that organization from the member list. Members who have a workspace seat but do not belong to the selected organization remain visible and show Not in this org instead of an editable organization-role control. Workspace admins can also manage the workspace seat assignment mode from Workspace Team Management. Automatic mode assigns members a seat when they open a pull request, while Manual mode lets admins assign seats individually. Billing Admin roles remain protected and cannot be changed from the role selector. Billing admins cannot be assigned a seat that consumes a license through Workspace Team Management. If a billing admin already has a seat, admins can still unassign it to free the license. Member users in SSO workspaces do not receive default access to Subscription and Billing, billing controls, or Team Management unless their workspace role or a custom role explicitly grants the corresponding permission.

CodeRabbit configuration

Enterprise SSO workspaces include a Workspace configuration page in the CodeRabbit UI. Workspace admins can use it to define CodeRabbit configuration that applies as a shared baseline across every organization in the workspace. In CodeRabbit Cloud, self-hosted Git provider organizations linked to a workspace can access the equivalent controls under Workspace Settings. Users who can view Organization Settings can view that workspace configuration, while saving settings or global overrides requires permission to update Organization Settings. Workspace global overrides take precedence over organization global overrides when both levels set the same key. See configuration inheritance for the full priority order.

What’s next

SCIM directory sync

Provision and deprovision users automatically from your identity provider after SAML SSO is active.

Roles and permissions

Review how CodeRabbit roles work so you can combine SSO with the right access model for your organization.

Support

Contact the CodeRabbit team if you need your service provider values or help troubleshooting the rollout.