Okta

Configure SAML 2.0 for Cursor

This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the Cursor app integration.

Contents


Supported features

Cursor supports the following features:

Prerequisites

Integrate the app in Okta

Retrieve your Audience URI from Cursor

  1. Sign in to Cursor with a team admin account.
  2. Go to Team Settings > Single Sign-On (SSO), and then go to Domain Verification Settings.
  3. Click Configure next to Domain Verification Settings to start the verification.
  4. Enter your domain, and then click Next.
  5. Follow the prompts to verify your organization domain.
  6. Go to Team Settings > Single Sign-On (SSO), and then go to SSO-Provider Connection Settings.
  7. Click Configure next to SSO-Provider Connection Settings to start the setup wizard.
  8. Select Okta SAML as your IdP.
  9. Note the Audience URI value that the wizard displays. You need it to complete the configuration in Okta.

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the Cursor app.
  4. Click Add Integration.
  5. On the General Settings tab, enter an Application label, or leave the default.
  6. Enter Cursor's Entity ID/Audience URI value that you retrieved earlier, and the ACS URL, as required by the integration.
  7. Click Done.
  8. On the Sign On tab, in the SAML Setup section, copy the URL of the Identity Provider metadata link. You need this URL to complete the dynamic configuration in Cursor.
  9. Go to the Assignments tab, click Assign > Assign to People (or Assign to Groups), and select the users who need access.
  10. Click Save, and then click Go Back.
  11. The integration doesn't work for users until you assign them to the app in Okta.

Configure SAML in Cursor

  1. Go back to Cursor's Team Settings > Single Sign-On (SSO), and click Configure next to SSO-Provider Connection Settings (the same screen you used to retrieve your audience URI).
  2. Click Continue, and then click Continue again.
  3. On Step 3: Set Identity Provider Metadata, select Dynamic configuration.
  4. Paste the metadata URL you copied from Okta into the Identity provider metadata URL field, and then click Continue.
  5. On Step 4: Configure SAML Attributes and Step 5: Assign Groups to the SAML App, click Continue to move past each step. You already configured these in Okta.
  6. On Step 6: Test Single Sign-On, click Continue to sign in.
  7. You're redirected to your Okta org. Enter your Okta credentials.
  8. After the test completes, you'll see a confirmation page. Your Cursor SSO connection is now fully configured.

Supported SAML attributes

Cursor supports these SAML attributes:

Attribute Value
firstName user.firstName
lastName user.lastName
email user.email
id user.getInternalProperty("id")

Verify SP-initiated SSO

  1. Go to the sign-in URL https://cursor.com/dashboard. Your Okta sign-in page opens.
  2. Enter your Okta credentials. You're signed in to your Cursor dashboard.