Available on Enterprise plan.
Enable SAML in Cube Cloud
First, we’ll enable SAML authentication in Cube Cloud. To do this, log in to Cube Cloud and- Navigate to Admin → Settings.
- On the Authentication & SSO tab, enable SAML.
- For a new integration, replace any prefilled Audience (SP Entity ID) value with the Single Sign-On URL shown directly above it.
Create a SAML Integration in Google Workspace
Next, we’ll create a SAML app integration for Cube Cloud in Google Workspace.- Log in to admin.google.com as an administrator, then navigate to Apps → Web and Mobile Apps from the left sidebar.
- Click Add App, then click Add custom SAML app:
- Enter a name for your application and click Next. You can optionally add a description and upload a logo for the application, but this is not required. Click Continue to go to the next screen.
- Take note of the SSO URL, Entity ID and Certificate values here, as we will need them when we finalize the SAML integration in Cube Cloud. Click Continue to go to the next screen.
- Enter the following values for the Service provider details section and click Continue.
- On the final screen, click Finish.
- From the app details page, click User access and ensure the app is ON for everyone:
Complete SAML configuration in Cube Cloud
In this step, we’ll finalise the configuration by entering the values from our SAML integration in Google into Cube Cloud.- Return to Admin → Settings → Authentication & SSO → SAML.
- Confirm that Audience (SP Entity ID) still matches the Single Sign-On URL exactly.
- Enter the following values in the SAML Settings section:
- Enable Auto-provision new users if you want users to be automatically created in Cube on their first login via this SAML provider. New users are assigned the Viewer role by default — see Default role for new users to choose a different role. Enable this if you are not using SCIM provisioning.
- Click Apply to save the changes.
Existing working Google Workspace integrations with a blank Audience do not
need to change immediately. A blank Audience disables audience validation. To
enable validation, update the Google Entity ID and Cube Audience (SP
Entity ID) together, keep another authentication method enabled, and test
SAML sign-in before you disable the fallback method.
Default role for new users
By default, users auto-provisioned via SAML receive the Viewer role. To assign a different role, expand the Advanced section of the SAML configuration form and pick from Default role for new users:- Developer, Explorer, or Viewer — Cube Cloud’s default roles.
- Any custom role defined in your account, listed below the divider.
rolesMap).
Admin status is not assignable through this picker — Admin is controlled
separately. To grant admin permissions, update the user’s role manually
under Admin → Users.
Test SAML authentication
To start using SAML authentication, use the single sign-on URL provided by Cube Cloud (typically<YOUR_CUBE_CLOUD_URL>/sso/saml) to log in to Cube Cloud.