SAML is available on Enterprise plan.
Configuration
To manage authentication settings, navigate to Admin → Settings of your Cube Cloud account, and switch to the Authentication & SSO tab. Use the toggles in Password, Google, and GitHub sections to enable or disable these authentication options.SAML
Use the toggle in the SAML section to enable or disable the authentication via an identity provider supporting the SAML protocol. Once it’s enabled, you’ll see the SAML Settings section directly below. Check the following guides to get tool-specific instructions on configuration:Google Workspace
Microsoft Entra ID
Okta
Match SAML service provider identifiers
Cube shows two service provider values in the SAML settings:
The Audience (SP Entity ID) value validates the audience in SAML responses.
It must exactly match the value configured in your identity provider. Leaving
the field blank disables audience validation and is supported only for
compatibility with existing configurations.
Some identity providers, including Amazon Federate, use one service provider
identifier for both the AuthnRequest issuer and the response audience. For
these providers, set Audience (SP Entity ID) in Cube to the Single
Sign-On URL, then use that same value as the identity provider’s Entity ID
or Audience.
Existing working SAML integrations do not need to change their Audience. When
you change an existing configuration, keep another authentication method
enabled until you have tested SAML sign-in in a separate browser session.