Cursor Sso IntegrationCAUTION
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: cursor-sso-integration description: 'Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. Triggers on "cursor sso", "cursor saml", "cursor oauth", "enterprise cursor auth", "cursor okta", "cursor entra", "cursor scim". ' allowed-tools: Read, Write, Edit, Bash(cmd:*) version: 1.19.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - cursor - authentication compatibility: Designed for Claude Code --- # Cursor SSO Integration ## Overview Integrate Cursor with the organization's identity provider through a phased, auditable SSO/SCIM rollout that preserves emergency recovery and least privilege. ## Instructions 1. Obtain approved SAML/SCIM values from the identity owner and validate them in a non-production or pilot tenant. 2. Pilot with a limited group, monitor sign-in/provisioning results, and correct attribute/group mappings before enforcement. 3. Enable organization-wide enforcement only after rollback/emergency access and deprovisioning paths are tested. 4. Retain redacted setup evidence and schedule access-review verification through the IdP. ## Output - An audited SSO configuration with scoped role mappings, tested SCIM provisioning, and a documented rollback/emergency-access path. ## Examples Pilot a single IdP group, confirm a new member receives the least-privilege Cursor role and a departed member is deprovisioned, then document the redacted IdP/Cursor audit evidence. If mapping is wrong, disable pilot enforcement and correct the group claim before organization-wide rollout. Configure Single Sign-On for Cursor using SAML 2.0 or OIDC. Available on Business and Enterprise plans. Supports Okta, Microsoft Entra ID (Azure AD), Google Workspace, and any SAML 2.0 / OIDC compliant IdP. ## Prerequisites - Cursor Business or Enterprise subscription - Admin access to both Cursor organization and Identity Provider - Verified company domain in Cursor admin dashboard - Understanding of SAML 2.0 or OIDC concepts ## SSO Configuration: Okta ### Step 1: Create SAML Application in Okta 1. Okta Admin Console > Applications > Create App Integration 2. Select **SAML 2.0** 3. App name: "Cursor IDE" ### Step 2: Configure SAML Settings ``` Single Sign-On URL (ACS URL): https://cursor.com/api/auth/saml/callback Audience URI (Entity ID): https://cursor.com/api/auth/saml Name ID format: EmailAddress Application username: Email Attribute Statements: email → user.email (Required) name → user.firstName + " " + user.lastName (Optional) ``` ### Step 3: Download IdP Metadata After creating the app in Okta: 1. Go to the app's "Sign On" tab 2. Click "Identity Provider metadata" link 3. Save the XML file ### Step 4: Upload to Cursor 1. Cursor Admin Dashboard > SSO 2. Select "SAML 2.0" 3. Upload the IdP metadata XML (or paste the metadata URL) 4. Save configuration ### Step 5: Test 1. Open Cursor incognito 2. Sign in with your `@company.com` email 3. Should redirect to Okta login 4. After auth, return to Cursor authenticated ## SSO Configuration: Microsoft Entra ID ### Step 1: Register Enterprise Application 1. Azure Portal > Entra ID > Enterprise applications > New application 2. Create your own application > "Cursor IDE" 3. Select "Integrate any other application you don't find in the gallery (Non-gallery)" ### Step 2: Configure SAML In the enterprise app > Single sign-on > SAML: ``` Basic SAML Configuration: Identifier (Entity ID): https://cursor.com/api/auth/saml Reply URL (ACS URL): https://cursor.com/api/auth/saml/callback Sign-on URL: https://cursor.com Attributes & Claims: Unique User Identifier: user.mail email: user.mail name: user.displayname ``` ### Step 3: Download Federation Metadata XML In Entra ID app > SAML Signing Certificate > Download "Federation Metadata XML" ### Step 4: Upload to Cursor Same as Okta Step 4: Admin Dashboard > SSO > Upload metadata. ## SSO Configuration: Google Workspace ### Step 1: Create SAML App 1. Google Admin Console > Apps > Web and mobile apps > Add app > Add custom SAML app 2. App name: "Cursor IDE" ### Step 2: Configure ``` ACS URL: https://cursor.com/api/auth/saml/callback Entity ID: https://cursor.com/api/auth/saml Name ID format: EMAIL Name ID: Basic Information > Primary email ``` ### Step 3: Download IdP Metadata Google provides this during app creation. Save the metadata XML. ### Step 4: Upload to Cursor Admin Dashboard > SSO > Upload metadata. ## SCIM Provisioning (Enterprise Only) SCIM 2.0 automatically syncs users and groups from your IdP to Cursor: ### What SCIM Handles | Operation | Trigger | Cursor Action | |-----------|---------|---------------| | User created in IdP | Okta/Entra creates user | Seat assigned in Cursor | | User deactivated in IdP | Okta/Entra deactivates | Seat revoked in Cursor | | Group membership change | User added/removed from group | Role updated in Cursor | ### SCIM Setup (Okta Example) 1. Cursor Admin Dashboard > SCIM > Generate SCIM token 2. In Okta > Cursor app > Provisioning > Enable SCIM 3. Configure: ``` SCIM connector base URL: https://cursor.com/api/scim/v2 Unique identifier field: email Authentication mode: Bearer token Bearer token: [paste token from Cursor] ``` 4. Enable: Create Users, Deactivate Users, Push Groups ## Domain Verification Required before SSO activation: 1. Cursor Admin Dashboard > Domains > Add domain 2. Add DNS TXT record: ``` Type: TXT Host: _cursor-verification Value: cursor-verify=xxxxxxxxxxxxxxxxxxxx ``` 3. Wait for DNS propagation (up to 48 hours, usually minutes) 4. Click "Verify" in Cursor admin ## Rollout Strategy ### Phase 1: Pilot (1 week) ``` [ ] Configure SSO with test users only [ ] Verify sign-in flow works end-to-end [ ] Test: new user SSO sign-in creates Cursor account [ ] Test: sig
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
- **Emergency access**: Keep one admin account with email/password login in case SSO is misconfigured
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__cursor-sso-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | CAUTION | B | 89 | first audit |
Questions
What does the Cursor Sso Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Cursor Sso Integration safe to install?
With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Cursor Sso Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Cursor Sso Integration work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.