Overview
Cloudraw connects to any identity provider that supports OpenID Connect (OIDC) with the authorization code flow and a client secret. Your people sign in at your provider with the account and MFA you already manage there.
In Settings→Identity & SSO→Your identity provider you can choose:
| Choice | Use it for | You enter |
|---|---|---|
| Okta | Okta organizations on an okta.com, oktapreview.com or okta-emea.com address | Your Okta org URL, client ID, client secret |
| JumpCloud | JumpCloud | Client ID, client secret (the issuer is filled in for you) |
| OpenID Connect | Any other OIDC provider: Keycloak, Ping, Authentik, Okta with a custom domain, and others | Issuer URL, client ID, client secret |
What Cloudraw needs from every provider:
- A confidential web client (client ID plus client secret) using the authorization code flow.
- The scopes
openid,profileandemail. - An
httpsissuer URL with a working discovery document at<issuer>/.well-known/openid-configuration. - A verified e-mail address for every user. Users whose e-mail is not verified at the provider are refused with "Your email address is not verified with your identity provider".
Step 1. Copy the redirect URI from Cloudraw
In the Cloudraw admin console open Settings→Identity & SSO, turn on Workspace sign-in if needed, and copy Redirect URI (add this at your provider). It looks like:
https://id-stg.cloudraw.com/ui/login/login/externalidp/callbackStep 2a. Okta: create the app integration
- Create the integrationIn the Okta Admin Console go to Applications→Applications→Create App Integration. Choose OIDC - OpenID Connect and Web Application.
- General settingsName:
Cloudraw. Grant type: Authorization Code only. - Sign-in redirect URIRemove the example and paste the Cloudraw redirect URI. Leave the sign-out redirect empty.
- AssignmentsChoose Limit access to selected groups and pick the groups that should use Cloudraw, or assign people later on the Assignments tab.
- Copy the credentialsSave. On the General tab, under Client Credentials, check that Client authentication is Client secret. Copy the Client ID and the Client secret.
- Note your Okta org URLIt is the address of your Okta sign-in page, for example
https://acme.okta.com. Use this without-adminand without a path.
Connect Okta in Cloudraw
- Choose OktaIn Settings→Identity & SSO→Your identity provider choose Okta.
- Fill in the fieldsOkta URL (issuer):
https://acme.okta.com. Then the client ID and client secret. Optionally set a button label and Only allow sign-in through the provider. - Save and testSign in from Cloudraw Connect on a test computer. You should land on your Okta sign-in page.
Using an Okta custom domain such as login.acme.com? The Okta choice accepts only okta.com-style addresses. Choose OpenID Connect instead and enter your custom domain as the issuer, exactly as it appears in https://login.acme.com/.well-known/openid-configuration.
Step 2b. JumpCloud
- Create the applicationIn the JumpCloud Admin Portal go to SSO Applications→Add New Application→Custom Application and choose OIDC.
- Configure itRedirect URI: the Cloudraw redirect URI. Client authentication type: Client Secret Basic. Login URL: your Cloudraw sign-in, or any URL your portal should open. Include the Email and Profile standard scopes.
- Copy the credentialsActivate the app and copy the Client ID and Client Secret. JumpCloud shows the secret once. Bind the user groups that should use Cloudraw.
- Connect in CloudrawChoose JumpCloud and paste the client ID and secret. The issuer
https://oauth.id.jumpcloud.comis set for you.
Step 2c. Any other OpenID Connect provider
- Create a client at your providerA confidential web client with the authorization code flow, a client secret, the Cloudraw redirect URI as the allowed redirect URI, and the scopes
openid profile email. - Find the issuer URLOpen
<your provider>/.well-known/openid-configurationin a browser and copy the"issuer"value exactly. - Connect in CloudrawChoose OpenID Connect, enter the issuer, client ID and client secret, and optionally a button label (default "Company sign-in").
| Provider | Typical issuer URL | Notes |
|---|---|---|
| Keycloak | https://sso.example.com/realms/<realm> | Client type OpenID Connect, Client authentication On, Standard flow On. Turn on Email verified for users, or they are refused. |
| PingOne | https://auth.pingone.com/<environment id>/as | Web app, Authorization Code, token endpoint auth Client Secret Basic or Post. |
| Authentik | https://auth.example.com/application/o/<slug>/ | OAuth2/OpenID provider, client type Confidential. |
Cloudraw removes a trailing / from the issuer you enter. If your provider's "issuer" value ends with a / (Authentik and Auth0 do), test a sign-in before you roll out. If it fails, contact support@cloudraw.com.
If saving fails with "The provider could not be configured. Check the client id, secret and issuer", check that the issuer opens the discovery document in a browser and that the ID and secret have no extra spaces.
People and groups
A person who signs in through your provider for the first time is added to People automatically and uses a seat. To have groups from your provider in Cloudraw, and to suspend people automatically when you deactivate them, set up SCIM below. Otherwise create Cloudraw groups.
Step 3 (optional). SCIM provisioning
In Cloudraw
- Turn on SCIMOpen Settings→Identity & SSO→SCIM provisioning and click Turn on SCIM.
- Copy the base URL and tokenThe token starts with
crwscim_and is shown once. The base URL looks likehttps://orchestrator-stg.cloudraw.com/v0/tenants/<workspace id>/scim/v2.
In Okta
- Enable SCIM on an app integrationOpen the Cloudraw app, then General→App Settings→Edit, and under Provisioning select SCIM. If your Okta org does not offer SCIM on an OIDC app, create a separate SWA app integration called
Cloudraw provisioningand enable SCIM there. - Connection settingsOn the new Provisioning→Integration tab click Edit:
- SCIM connector base URL: the Cloudraw base URL
- Unique identifier field for users:
userName - Supported provisioning actions: Push New Users, Push Profile Updates, Push Groups
- Authentication Mode: HTTP Header. Paste the
crwscim_…token as the Bearer token.
- Turn on actionsUnder Provisioning→To App enable Create Users, Update User Attributes and Deactivate Users.
- Push groupsOn the Push Groups tab, push the groups you want to use in Cloudraw access rules.
Okta's userName must be the person's e-mail address. That is Okta's default when usernames are e-mail addresses. Deactivating a user in Okta suspends them in Cloudraw, and their devices lose access.
Other providers
Any provider that supports SCIM 2.0 with a bearer token works. Cloudraw supports Users and Groups, filtering by userName eq "…", externalId and displayName, and PATCH. It does not support bulk operations, sorting or password changes.
MFA: Okta Verify and others
For people who sign in through Okta, JumpCloud or another provider, MFA happens at your provider. Cloudraw does not add its own e-mail code, unless the workspace sent Cloudraw invitations before you connected the provider. See Two-factor authentication.
To require Okta Verify for Cloudraw:
- Enroll the authenticatorUnder Security→Authenticators, make sure Okta Verify is set up and an enrollment policy asks users to enroll it.
- Create an app sign-in policyUnder Security→Authentication Policies, add a policy, for example Cloudraw, with a rule where User must authenticate with is Password + Another factor or Any 2 factor types. Optionally require a phishing-resistant authenticator.
- Assign the policyOn the policy's Applications tab, add the Cloudraw app.
JumpCloud: turn on MFA for users under User Management, or with Conditional Access policies on the Cloudraw application. Keycloak: add OTP or WebAuthn to the realm's browser flow.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
| Provider says the redirect URI is not allowed | The redirect URI at the provider is not exactly the one Cloudraw shows. Paste it again. |
| Okta: "User is not assigned to the client application" | Assign the user, or their group, to the Cloudraw app in Okta. |
| Cloudraw: "issuer must be your Okta org URL" | Use https://<org>.okta.com. For a custom domain choose OpenID Connect. |
| Cloudraw Connect: "Your email address is not verified with your identity provider" | Mark the user's e-mail as verified at the provider (for example in Keycloak), or make sure the provider sends email_verified. |
| SCIM test fails with 401 | Wrong or rotated token. Generate a new one in Cloudraw and paste it into the provider. |
| SCIM: "a user with this userName already exists" | A person with that e-mail already exists in Cloudraw, for example added by hand. Remove the duplicate, or let Okta import and match it. |