Invite users to sign in
Complete your Single Sign-On (SSO) setup with SCIM or JIT provisioning in SonarQube Cloud and invite users to sign in.
After configuring Single Sign-On (SSO), complete your setup by verifying your domain, configuring your recovery account, setting up one-click access, and inviting users to sign in. Domain verification can be done during SSO setup or after it's already configured.
After configuring Single Sign-On (SSO), set up one-click access, invite users to sign in, and finalize your SSO setup.
If you don't use SCIM provisioning, create or verify first the user groups in SonarQube Cloud if not already done. See Managing groups in SonarQube Cloud if using JIT provisioning.
Step 1: Configure one-click access
SonarQube Cloud uses the Service Provider (SP) initiated SSO (IdP-initiated SSO is not supported except through the Okta dashboard if you set up SSO through the Okta Express Configuration). It means that SSO users must go to the login page of SonarQube Cloud.
Make sure to verify your company's email domain to avoid one-time email verification during SSO login.
If you want to use a shortcut link to access the SSO login, use https://sonarcloud.io/login/sso?enterprise_key=<enterprise_key>. You can copy this link directly from SonarQube Cloud as follows:
Retrieve your enterprise. See Retrieving and viewing your enterprise for more details.
Go to Administration > SSO & Provisioning.
Expand the Single sign-on section and select Copy link in front of the Configure one-click access field.
Step 2: Invite users to sign in
You can now invite users to sign in to SonarQube Cloud with SSO. To do so, send them the login URL of your enterprise.
To retrieve the login URL of your enterprise:
Retrieve your enterprise. See Retrieving and viewing your enterprise for more details.
Go to Administration > SSO & Provisioning.
Expand the Single sign-on & Domain verification section and select Copy link in front of the Invite users to sign in field. You can now paste the copied URL to your invite message.

Users should check that they have access to their organization(s) in SonarQube Cloud. If they used the DevOps platform service authentication before, they should check that:
They can perform their tasks as before.
If using Personal Access Tokens (PAT): They can generate their analysis tokens with their SSO account. (They can still use their DevOps platform service (DOP) account tokens to execute analysis as long as their DOP account still exists). Note that from the Team plan, it's highly recommended to use Scoped Organization Tokens (SOT) instead of PATs.
Step 3: Terminate
Sign in to SonarQube Cloud with your DevOps Platform (DOP) account and grant your SSO account the Administer Enterprise permissions. See Managing the enterprise-related permissions for more details.
If you transitioned from a DevOps platform authentication service to SSO, you can remove the end users’ DOP accounts from the SonarQube Cloud organizations (see Adding organization members) and these users can delete their DOP account within SonarQube Cloud (see Deleting your account).
We recommend that you keep at least one or a few admin or service user accounts in the DevOps Platform. This is especially crucial if you use Bitbucket Cloud, as you are currently unable to link a SonarQube Cloud organization with a Bitbucket Cloud workspace using an SSO account.
Sign in to SonarQube Cloud with SSO and configure your recovery account for your enterprise. See Recovery account for SSO for more details.
This step is strongly advised for all enterprise administrators in order to be able to recover access to your enterprise in case SSO login becomes unavailable.
Related pages
Last updated
Was this helpful?

