Agent skill

Cursor Sso Integration

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

MITAuto-check passedBackend & APIs

Install Cursor Sso Integration

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-sso-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace cursor-sso-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/cursor-sso-integration .claude/skills/cursor-sso-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cursor-sso-integration
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
757 words
Files
7 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

  • Works in 12 steps: Create SAML Application in Okta → Configure SAML Settings → Download IdP Metadata → …
  • Enterprise cursor auth
  • SKILL.md covers Overview, Instructions, Output and Examples, plus 7 more sections
  • Reaches cursor.com

What it does

Cursor Sso Integration is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. Triggers on "cursor sso", "cursor saml", "cursor oauth", "enterprise cursor auth", "cursor okta", "cursor entra", "cursor scim".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/errors.md`, `references/examples.md` and `references/rollout-strategy.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authentication, OAuth and OpenID Connect and Cloud office suites. It works with Okta, Microsoft Entra ID and Google Workspace. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Enterprise cursor auth
  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “cursor sso”
  • “cursor saml”
  • “cursor oauth”
  • “/cursor-sso-integration”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(cmd:*)

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Create SAML Application in Okta
  2. Configure SAML Settings
  3. Download IdP Metadata
  4. Upload to Cursor
  5. Test
  6. Register Enterprise Application
  7. Configure SAML
  8. Download Federation Metadata XML
  9. Upload to Cursor
  10. Create SAML App
  11. Configure
  12. Download IdP Metadata

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cursor.com

    Also links to:

    • docs.cursor.com
    • docs.oasis-open.org
    • developer.okta.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Cursor Sso Integration loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 757 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 757 words, ~2,007 tokens.

Download SKILL.mdSave it as .claude/skills/cursor-sso-integration/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
cursor-sso-integration
description
Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. Triggers on "cursor sso", "cursor saml", "cursor oauth", "enterprise cursor auth", "cursor okta", "cursor entra", "cursor scim".
allowed-tools
Read, Write, Edit, Bash(cmd:*)
compatibility
Designed for Claude Code
version
1.19.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, cursor, authentication

Cursor SSO Integration

Overview

Integrate Cursor with the organization's identity provider through a phased, auditable SSO/SCIM rollout that preserves emergency recovery and least privilege.

Instructions

  1. Obtain approved SAML/SCIM values from the identity owner and validate them in a non-production or pilot tenant.
  2. Pilot with a limited group, monitor sign-in/provisioning results, and correct attribute/group mappings before enforcement.
  3. Enable organization-wide enforcement only after rollback/emergency access and deprovisioning paths are tested.
  4. Retain redacted setup evidence and schedule access-review verification through the IdP.

Output

  • An audited SSO configuration with scoped role mappings, tested SCIM provisioning, and a documented rollback/emergency-access path.

Examples

Pilot a single IdP group, confirm a new member receives the least-privilege Cursor role and a departed member is deprovisioned, then document the redacted IdP/Cursor audit evidence. If mapping is wrong, disable pilot enforcement and correct the group claim before organization-wide rollout.

Configure Single Sign-On for Cursor using SAML 2.0 or OIDC. Available on Business and Enterprise plans. Supports Okta, Microsoft Entra ID (Azure AD), Google Workspace, and any SAML 2.0 / OIDC compliant IdP.

Prerequisites

  • Cursor Business or Enterprise subscription
  • Admin access to both Cursor organization and Identity Provider
  • Verified company domain in Cursor admin dashboard
  • Understanding of SAML 2.0 or OIDC concepts

SSO Configuration: Okta

Step 1: Create SAML Application in Okta
  1. Okta Admin Console > Applications > Create App Integration
  2. Select SAML 2.0
  3. App name: "Cursor IDE"
Step 2: Configure SAML Settings
Single Sign-On URL (ACS URL):
  https://cursor.com/api/auth/saml/callback

Audience URI (Entity ID):
  https://cursor.com/api/auth/saml

Name ID format: EmailAddress
Application username: Email

Attribute Statements:
  email    → user.email       (Required)
  name     → user.firstName + " " + user.lastName  (Optional)
Step 3: Download IdP Metadata

After creating the app in Okta:

  1. Go to the app's "Sign On" tab
  2. Click "Identity Provider metadata" link
  3. Save the XML file
Step 4: Upload to Cursor
  1. Cursor Admin Dashboard > SSO
  2. Select "SAML 2.0"
  3. Upload the IdP metadata XML (or paste the metadata URL)
  4. Save configuration
Step 5: Test
  1. Open Cursor incognito
  2. Sign in with your @company.com email
  3. Should redirect to Okta login
  4. After auth, return to Cursor authenticated

SSO Configuration: Microsoft Entra ID

Step 1: Register Enterprise Application
  1. Azure Portal > Entra ID > Enterprise applications > New application
  2. Create your own application > "Cursor IDE"
  3. Select "Integrate any other application you don't find in the gallery (Non-gallery)"
Step 2: Configure SAML

In the enterprise app > Single sign-on > SAML:

Basic SAML Configuration:
  Identifier (Entity ID):     https://cursor.com/api/auth/saml
  Reply URL (ACS URL):        https://cursor.com/api/auth/saml/callback
  Sign-on URL:                https://cursor.com

Attributes & Claims:
  Unique User Identifier:     user.mail
  email:                      user.mail
  name:                       user.displayname
Step 3: Download Federation Metadata XML

In Entra ID app > SAML Signing Certificate > Download "Federation Metadata XML"

Step 4: Upload to Cursor

Same as Okta Step 4: Admin Dashboard > SSO > Upload metadata.

SSO Configuration: Google Workspace

Step 1: Create SAML App
  1. Google Admin Console > Apps > Web and mobile apps > Add app > Add custom SAML app
  2. App name: "Cursor IDE"
Step 2: Configure
ACS URL:        https://cursor.com/api/auth/saml/callback
Entity ID:      https://cursor.com/api/auth/saml
Name ID format: EMAIL
Name ID:        Basic Information > Primary email
Step 3: Download IdP Metadata

Google provides this during app creation. Save the metadata XML.

Step 4: Upload to Cursor

Admin Dashboard > SSO > Upload metadata.

SCIM Provisioning (Enterprise Only)

SCIM 2.0 automatically syncs users and groups from your IdP to Cursor:

Show full SKILL.md (306 more words)Show less
What SCIM Handles
OperationTriggerCursor Action
User created in IdPOkta/Entra creates userSeat assigned in Cursor
User deactivated in IdPOkta/Entra deactivatesSeat revoked in Cursor
Group membership changeUser added/removed from groupRole updated in Cursor
SCIM Setup (Okta Example)
  1. Cursor Admin Dashboard > SCIM > Generate SCIM token

  2. In Okta > Cursor app > Provisioning > Enable SCIM

  3. Configure:

    SCIM connector base URL: https://cursor.com/api/scim/v2
    Unique identifier field: email
    Authentication mode: Bearer token
    Bearer token: [paste token from Cursor]
  4. Enable: Create Users, Deactivate Users, Push Groups

Domain Verification

Required before SSO activation:

  1. Cursor Admin Dashboard > Domains > Add domain

  2. Add DNS TXT record:

    Type:  TXT
    Host:  _cursor-verification
    Value: cursor-verify=xxxxxxxxxxxxxxxxxxxx
  3. Wait for DNS propagation (up to 48 hours, usually minutes)

  4. Click "Verify" in Cursor admin

Rollout Strategy

Phase 1: Pilot (1 week)
[ ] Configure SSO with test users only
[ ] Verify sign-in flow works end-to-end
[ ] Test: new user SSO sign-in creates Cursor account
[ ] Test: sign-out and re-sign-in preserves settings
[ ] Test: IdP session timeout triggers re-auth in Cursor
[ ] Document any issues or friction points
Phase 2: Gradual Rollout (2 weeks)
[ ] Enable SSO for one team/department
[ ] Monitor sign-in success rate in admin dashboard
[ ] Collect feedback on the auth experience
[ ] Resolve any IdP attribute mapping issues
Phase 3: Organization-Wide
[ ] Enable SSO requirement for all users
[ ] Disable password-based login (optional)
[ ] Enable SCIM for automatic provisioning
[ ] Set up IdP group → Cursor role mapping
[ ] Document SSO in company IT wiki

Troubleshooting

IssueCauseFix
"SAML Response Invalid"Wrong ACS URL or Entity IDVerify URLs match exactly
User not created after SSOSCIM not enabled or email mismatchCheck SCIM logs in IdP
"Domain not verified"DNS record not propagatedWait, then re-verify
Redirect loop after SSOBrowser cookies corruptedClear cookies for cursor.com
SSO works but wrong roleGroup mapping misconfiguredCheck IdP group assignments
"No seat available"All seats assignedPurchase more seats or revoke unused

Enterprise Considerations

  • MFA enforcement: Apply MFA policy at the IdP level (Okta/Entra). Cursor defers to IdP for MFA.
  • Session timeout: Configure session lifetime in IdP. Cursor respects IdP session expiry.
  • Emergency access: Keep one admin account with email/password login in case SSO is misconfigured
  • Compliance: SSO provides centralized access logging at the IdP level for audit trails
  • Cost: SSO is included in Business ($40/user/mo) and Enterprise plans. No additional SSO fee.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/.curated/cursor-sso-integration of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/errors.md
  • references/examples.md
  • references/rollout-strategy.md
  • references/saml-2.0-configuration.md
  • references/testing-sso.md
  • references/user-provisioning.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Cursor Sso Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cursor Sso Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cursor Sso Integration this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Implementing Google Workspace Sso Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Identity Access Managementsickn33/agentic-awesome-skills47k1 repos~2.9kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills202—~1.5kAutomated safety check: PassMIT

Similar skills

  • Implementing Google Workspace Sso Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Identity Access Management

    sickn33/agentic-awesome-skills

    Set up and manage SSO, SCIM provisioning, and MFA for startup teams using Google Workspace, Okta, or Azure AD.

    47k GitHub starsUsed in 1 repo~2.9k tokens
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Google Workspace

    RedWoodOG/Hermes-Desktop

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

    177 GitHub stars~2.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Cursor Sso Integration

What does Cursor Sso Integration do?

Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. Cursor Sso Integration is an agent skill from jeremylongshore/tons-of-skills-marketplace.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

When should I use Cursor Sso Integration?

Cursor Sso Integration fits situations like: enterprise cursor auth; tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Cursor Sso Integration in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-sso-integration -a claude-code`. Or copy the skill folder (skills/.curated/cursor-sso-integration in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/cursor-sso-integration in your project. Claude Code loads it when a task matches its description.

How do I install Cursor Sso Integration in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-sso-integration -a codex`. Or copy the skill folder (skills/.curated/cursor-sso-integration in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/cursor-sso-integration in your project. Codex loads it when a task matches its description.

Can I use Cursor Sso Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-sso-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cursor-sso-integration, .gemini/skills/cursor-sso-integration, .github/skills/cursor-sso-integration and .opencode/skills/cursor-sso-integration in your project.

What does Cursor Sso Integration need to run?

SKILL.md names no scripts, command-line tools or credentials: Cursor Sso Integration is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Cursor Sso Integration access the network?

SKILL.md names 4 domains. In commands or code: cursor.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.cursor.com, docs.oasis-open.org and developer.okta.com. This is read from the text; nothing was executed.

Is Cursor Sso Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cursor Sso Integration use?

Cursor Sso Integration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cursor Sso Integration use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Cursor Sso Integration?

Skills that share tags, products or a category with Cursor Sso Integration: Implementing Google Workspace Sso Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Identity Access Management (sickn33/agentic-awesome-skills, 47k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cursor Sso Integration?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.