Using the setup assistant (generic operation)
This page explains how to configure SSO with SonarQube Cloud’s setup assistant if you use another identity provider than Okta or Microsoft Entra ID.
The generic operation to configure SSO with SonarQube Cloud's setup assistant is as follows:
In SonarQube Cloud, retrieve your enterprise. See Managing your enterprise for more details.
Select Administration > Single Sign-On. The Single Sign-On page opens.
Select Open Configuration and then Get Started. The setup assistant opens.
Select Custom SAML and select Next.
Follow the steps described below.
If you use Okta, see SAML SSO with Okta.
If you use Microsoft Entra ID, see SAML SSO with Entra ID.
The SSO setup assistant is a recent addition. If you previously configured SSO using the older method, your setup remains unaffected. However, to leverage the benefits of the new SSO setup assistant, you may delete your existing configuration and create a new one.
Step 1: Create the SonarQube Cloud application in your identity provider
Create the SonarQube Cloud application in your identity provider.
Copy the Service Provider Identity ID field value from the setup assistant and paste it into the corresponding field in your identity provider.
Copy the Single Sign-On URL field value from the setup assistant and paste it into the corresponding field in your identity provider.
In the setup assistant, select Next to go to the step 2. Configure Connection.

Step 2: Configure the connection
The operation is different depending on whether your identity provider supports the SAML metadata URL field (URL used by SonarQube Cloud to access metadata information) or not.
Metadata URL supported
In your SonarQube Cloud application in your identity provider, copy the value of the field corresponding to the SAML metadata URL .
Paste it into the Metadata URL field in the Automatic tab of the setup assistant page.
In the assistant, select Create Connection and Proceed. SonarQube Cloud is trying to connect to your Identity Provider. If the connection is established, the assistant moves to step 3. Attribute Mapping.

Metadata URL not supported
In the assistant, select the Manual tab.
In your identity provider, copy the value of the SSO login URL field and paste it into Single Sign-On Login URL in the assistant.
In your identity provider, download the certificate and upload it to the assistant.
In the assistant, select Create Connection and Proceed. SonarQube Cloud is trying to connect to your Identity Provider. If the connection is established, the assistant moves to step 3. Attribute Mapping.

Step 3: Set up the attributes
In your identity provider, create the attributes for name, login, email, and groups (the group attribute is used for automatic group synchronization. To do so, for each attribute, copy the attribute name from the assistant and paste it into the attribute’s name field in your identity provider.
In the assistant, select Next to go to step 4. Test SSO.
Step 4: Test SSO
Select the Test Connection button. The test is started and the results are displayed on the page as illustrated below.

If the test was successful, select Done.
Related pages
Step 1: Verify the user groups Step 3: Invite users to sign in Step 4: Terminate SSO setup Editing SSO configuration Deleting SSO configuration
Last updated
Was this helpful?

