Configure SAML 2.0 for Cursor
This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the Cursor app integration.
Contents
Supported features
Cursor supports the following features:
- SP-initiated SSO
- IdP-initiated SSO
- Just-In-Time (JIT) provisioning
Prerequisites
- You have an Okta admin role with permission to manage apps.
- You have admin access to your Cursor team (a team admin account).
Integrate the app in Okta
Retrieve your Audience URI from Cursor
- Sign in to Cursor with a team admin account.
- Go to Team Settings > Single Sign-On (SSO), and then go to Domain Verification Settings.
- Click Configure next to Domain Verification Settings to start the verification.
- Enter your domain, and then click Next.
- Follow the prompts to verify your organization domain.
- Go to Team Settings > Single Sign-On (SSO), and then go to SSO-Provider Connection Settings.
- Click Configure next to SSO-Provider Connection Settings to start the setup wizard.
- Select Okta SAML as your IdP.
- Note the Audience URI value that the wizard displays. You need it to complete the configuration in Okta.
Configure the app in Okta
- In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
- Click Browse App Catalog.
- Search for and select the Cursor app.
- Click Add Integration.
- On the General Settings tab, enter an Application label, or leave the default.
- Enter Cursor's Entity ID/Audience URI value that you retrieved earlier, and the ACS URL, as required by the integration.
- Click Done.
- On the Sign On tab, in the SAML Setup section, copy the URL of the Identity Provider metadata link. You need this URL to complete the dynamic configuration in Cursor.
- Go to the Assignments tab, click Assign > Assign to People (or Assign to Groups), and select the users who need access.
- Click Save, and then click Go Back.
The integration doesn't work for users until you assign them to the app in Okta.
Configure SAML in Cursor
- Go back to Cursor's Team Settings > Single Sign-On (SSO), and click Configure next to SSO-Provider Connection Settings (the same screen you used to retrieve your audience URI).
- Click Continue, and then click Continue again.
- On Step 3: Set Identity Provider Metadata, select Dynamic configuration.
- Paste the metadata URL you copied from Okta into the Identity provider metadata URL field, and then click Continue.
- On Step 4: Configure SAML Attributes and Step 5: Assign Groups to the SAML App, click Continue to move past each step. You already configured these in Okta.
- On Step 6: Test Single Sign-On, click Continue to sign in.
- You're redirected to your Okta org. Enter your Okta credentials.
- After the test completes, you'll see a confirmation page. Your Cursor SSO connection is now fully configured.
Supported SAML attributes
Cursor supports these SAML attributes:
| Attribute |
Value |
| firstName |
user.firstName |
| lastName |
user.lastName |
| email |
user.email |
| id |
user.getInternalProperty("id") |
Verify SP-initiated SSO
- Go to the sign-in URL
https://cursor.com/dashboard. Your Okta sign-in page opens.
- Enter your Okta credentials. You're signed in to your Cursor dashboard.