These docs are for Cribl Stream 4.4 and are no longer actively maintained.
See the latest version (4.11).
Cribl.Cloud SSO Setup
The pages in this section outline how, with a Cribl.Cloud Enterprise plan, you can set up a Single Sign-On (SSO) integration between your identity provider and your Cribl.Cloud portal. The following pages cover both OIDC and SAML authentication options:
- Common SSO Setup Steps
- OIDC/Okta Setup Example
- SAML/Okta Setup Examples
- SAML/Microsoft Entra ID Setup Examples
- Final SSO Steps & Troubleshooting
SSO integration requires you to perform certain configuration steps in your identity provider (IDP), and to then submit corresponding information to Cribl. As of Cribl Stream 4.0, you can submit these details directly on your Cribl.Cloud portal’s Organization page.

This section covers both sides of the process. For additional details specifically about integrating Cribl Stream with Okta, see SSO/Okta Configuration.
The general steps to set up a Single Sign-On (SSO) integration between your identity provider and your Cribl.Cloud portal are:
Invite at least one SSO admin to your Cribl.Cloud Organization from a fallback, separate email domain.
In your identity provider (IDP), configure user groups that map to Cribl.Cloud’s four predefined Roles.
In your IDP, create an OIDC or SAML application.
If creating an OIDC application, you must use backchannel authentication. Cribl.Cloud does not support front-channel authentication via OIDC.
Submit your app’s configuration details to Cribl on your Cribl.Cloud portal’s Organization page > SSO tab. (This will complete your SSO setup on the Cribl side.)
In your IDP, assign groups to your users, matching the Role that each group of users should have in Cribl.Cloud.
In your IDP, assign the OIDC/SAML app to the Organization’s owner, and to other Cribl.Cloud users.