Before you begin
You will need Admin permissions in your IdP, the ability to add a TXT record to the DNS settings for your domain, the Admin role in your ClickHouse Cloud organization. We recommend setting up a direct link to your organization in addition to your SAML connection to simplify the login process. Each IdP handles this differently. Read on for how to do this for your IdP.How it works
Once SAML SSO is configured, users sign in through a service-provider-initiated flow:- The user goes to
https://console.clickhouse.cloudand enters their email address (or uses your organization’s direct link). - ClickHouse Cloud redirects them to your identity provider to authenticate.
- On success, the identity provider redirects them back to ClickHouse Cloud.
- ClickHouse Cloud signs them in, provisioning the account just-in-time on first login and assigning your configured default role.
How to configure your IdP
If SAML is already enabled and you need admin access, see Configure your admin user or Troubleshooting.Access Organization settings
Click on your organization name in the lower left corner and select Organization details.
Enable SAML single sign-on
Click the toggle next to
Enable SAML single sign-on. Leave this screen open as you will refer back to it several times during the setup process.Create an application in your identity provider
Create an application within your identity provider and copy the values on the
Enable SAML single sign-on screen to your identity provider configuration. For more information on this step, refer to your specific identity provider below.Add the metadata URL to your SAML configuration
Obtain the
Metadata URL from your SAML provider. Return to ClickHouse Cloud, click Next: Provide metadata URL and paste the URL in the text box.Get domain verification code
Click
Next: Verify your domains. Enter your domain in the text box and click Check domain. The system will generate a random verification code for you to add to a TXT record with your DNS provider.Verify your domain
Create a TXT record with your DNS provider. Copy the
TXT record name to the TXT record Name field with your DNS provider. Copy the Value to the Content field with your DNS provider. Click Verify and Finish to complete the process.It may take several minutes for the DNS record to update and be verified. You may leave the setup page and return later to complete the process without restarting. The verification value is valid for 48 hours from when it is first generated.
Update default role and session timeout
Once the SAML setup is complete, you can set the default role(s) all users will be assigned when they log in and also adjust session timeout settings. For a list of available system roles that may be assigned, please review Console roles and permissions.
Configure your admin user
Users configured with a different authentication method will be retained until an admin in your organization removes them.
- Log out of ClickHouse Cloud.
- In your identity provider, assign the admin user to the ClickHouse applications.
- Ask the user to log in via https://console.clickhouse.cloud/?connection={orgId} (shortcut URL). This may be via a bookmark you created in the prior steps. The user won’t appear in ClickHouse Cloud until their first login.
- If the default SAML role is anything other than Admin, the user may need to log out and log back in with their original authentication method to update the new SAML user’s role.
- For email + password accounts, please use
https://console.clickhouse.cloud/?with=email. - For social logins, please click the appropriate button (Continue with Google or Continue with Microsoft)
- For email + password accounts, please use
email in ?with=email above is the literal parameter value, not a placeholder- Log out one more time and log back in via the shortcut URL to complete the last step below.
Configure your identity provider
- Okta
- Google
- Azure (Microsoft)
- Duo
You will configure two App Integrations in Okta for each ClickHouse organization: one SAML app and one bookmark to house your direct link.
Create a group to manage access
- Log in to your Okta instance as an Administrator.
- Select Groups on the left.
- Click Add group.
- Enter a name and description for the group. This group will be used to keep users consistent between the SAML app and its related bookmark app.
- Click Save.
- Click the name of the group that you created.
- Click Assign people to assign users you would like to have access to this ClickHouse organization.
Create a bookmark app to enable users to seamlessly log in
- Select Applications on the left, then select the Applications subheading.
- Click Browse App Catalog.
- Search for and select Bookmark App.
- Click Add integration.
- Select a label for the app.
- Enter the URL as
https://console.clickhouse.cloud/?connection={organizationid} - Go to the Assignments tab and add the group you created above.
Create a SAML app to enable the connection
- Select Applications on the left, then select the Applications subheading.
- Click Create App Integration.
- Select SAML 2.0 and click Next.
- Enter a name for your application and check the box next to Don’t display application icon to users then click Next.
-
Use the following values to populate the SAML settings screen.
-
Enter the following Attribute Statement.
- Click Next.
- Enter the requested information on the Feedback screen and click Finish.
- Go to the Assignments tab and add the group you created above.
- On the Sign On tab for your new app, click the Copy metadata URL button.
- Return to Add the metadata URL to your SAML configuration to continue the process.
Troubleshooting
Admin permissions are missing after SAML sign-in
Admin permissions are missing after SAML sign-in
Cause: your new SAML account receives the configured default SAML role. If that role isn’t Admin, the account won’t have admin permissions, even if your original account has the Admin role. ClickHouse Cloud doesn’t automatically link SAML and non-SAML accounts.Fix: sign in through SAML once so the new user appears in ClickHouse Cloud. Then log out and sign in with your original admin account to assign the Admin role to the SAML user:
- For email-and-password accounts, use the email sign-in link to bypass the automatic SAML redirect. The
emailin?with=emailis a literal value, not a placeholder for your email address. - For Google or Microsoft accounts, select Continue with Google or Continue with Microsoft.
There could be a misconfiguration in the system or a service outage
There could be a misconfiguration in the system or a service outage
Cause: identity-provider-initiated login, which isn’t supported.Fix: use the direct link
https://console.clickhouse.cloud/?connection={organizationid}. Follow the instructions for your identity provider above to make this the default login method for your users.You're directed to your identity provider, then back to the login page
You're directed to your identity provider, then back to the login page
Cause: the identity provider doesn’t have the email attribute mapping.Fix: follow the instructions for your identity provider above to configure the user email attribute, then log in again.
User isn't assigned to this application
User isn't assigned to this application
Cause: the user hasn’t been assigned to the ClickHouse application in the identity provider.Fix: assign the user to the application in the identity provider and log in again.
You always land in the same organization with multiple SAML orgs
You always land in the same organization with multiple SAML orgs
Cause: you’re still logged in to the first organization.Fix: log out, then log in to the other organization.
The URL briefly shows access denied
The URL briefly shows access denied
Cause: your email domain doesn’t match the domain configured.Fix: reach out to support for assistance resolving this error.
Frequently asked questions
Does ClickHouse Cloud support identity-provider-initiated sign-in?
Does ClickHouse Cloud support identity-provider-initiated sign-in?
No — only service-provider-initiated flows. Users navigate to
https://console.clickhouse.cloud and enter their email to be redirected to your identity provider. Set up a bookmark or direct link (https://console.clickhouse.cloud/?connection={organizationid}) so users don’t have to remember the URL.How do I use SAML SSO with multiple organizations?
How do I use SAML SSO with multiple organizations?
ClickHouse Cloud supports multi-organization SSO with a separate connection per organization.Your first login to each organization must use its direct link (
https://console.clickhouse.cloud/?connection={organizationId}). This first login provisions your account in that organization. If your organization has SCIM enabled, you can skip this step because your account will already be provisioned.For subsequent sign-ins, log in to any of your SAML organizations. Your other SAML organizations are available in the organization switcher in the console sidebar, and selecting one signs you into that organization through its SSO.If you don’t want users on your domain routed to an organization automatically when they enter their email at https://console.clickhouse.cloud, open a support ticket to remove that behavior.Why do I see multiple accounts for the same user?
Why do I see multiple accounts for the same user?
ClickHouse Cloud doesn’t automatically link SSO and non-SSO accounts, so a user who has signed in both ways may appear more than once in your user list even with the same email address.
Next steps
- Manage cloud users — manage permissions and restrict access to SAML connections only.
- SCIM provisioning — automate user and group provisioning with Okta or Microsoft Entra ID.
- Console roles and permissions — the roles you can assign as the default SAML role.