Skip to content
SSO and SCIM

Sign people in through your identity provider with SAML 2.0 or OIDC, and sync users and groups over SCIM 2.0. Every chat, dashboard, and AI answer then runs under the access your directory groups grant.

14-day trial. No credit card required.

Members

Provisioned by Okta over SCIM
104 members · 7 groups
NameStatus

Powering analytics for 5000+ teams worldwide

Exa logoTiger Data logoPurpose logoGumloop logoComposio logoFullscript logoShiftrx logoDrata logoExa logoTiger Data logoPurpose logoGumloop logoComposio logoFullscript logoShiftrx logoDrata logo

Provisioning

Assign Basedash in Okta or Entra ID and people arrive with their name, title, and groups, no invite email needed. Team changes update their groups, and offboarding deactivates their membership while keeping their work and history.

Okta → Basedash

SCIM 2.0
  • Ana RuizJoined · Product, Data2m
  • Dana KimMoved to Finance18m
  • Tom BeckerDeactivated1h

Tom Becker

Deactivated

Unassigned in Okta

Organization access
Removed
Dashboards and charts
Kept · 6
Audit history
Kept

Group-based access

Grant each data source to the groups that should query it, and Basedash enforces it in chat, dashboards, exports, and SQL. On Postgres, row-level security reads the same groups, so an AI answer only covers rows the asker may see.

Row-level security on Postgres

basedash.groups = 'Finance'
create policy invoices_by_group on invoices
  for select using (
    region = any (string_to_array(
      current_setting('basedash.groups', true), ','))
  );

Single sign-on

Connect Okta, Entra ID, Google Workspace, or any SAML 2.0 or OIDC provider and verify your domain with a DNS record. From then on, everyone on that domain signs in through your IdP, and new hires can join automatically.

Domains

Settings

  • acme.comSAML 2.0 · Okta · Auto-join onVerified
  • acme.ioSAML 2.0 · OktaVerified
  • acme-labs.comWaiting for the DNS TXT recordPending

Sign in to Basedash

[email protected]

acme.com signs in with single sign-on

On the record

Each SCIM create, update, and deactivation is logged with the token that sent it, next to sign-ins, queries, and AI tool calls. Export it to CSV or pull it into your SIEM through the API to answer access reviews.

Audit logs

Today

scim.user_deactivated

Actor
SCIM token
Token
Okta production
Change
active: true → false

What's included

SSO and SCIM come with the Enterprise plan, in the cloud or self-hosted, and an organization admin sets both up in Settings.

  • Enterprise plan

    Included with Enterprise, in the cloud or self-hosted.

  • SAML 2.0 and OIDC

    Okta, Entra ID, Google Workspace, OneLogin, and more.

  • SCIM 2.0

    Users, groups, and memberships, with discovery endpoints.

  • No invite emails

    Provisioned people can sign in as soon as they're assigned.

  • Members by default

    SCIM never grants admin; roles stay a Basedash decision.

  • History kept

    Deactivation removes access but keeps dashboards and logs.

  • Named tokens

    Shown once, stored hashed, with last-used dates and revoke.

  • Works self-hosted

    The same endpoints at your own base URL, no extra setup.

Which providers work, what syncs, and how directory groups turn into access in Basedash.

Which identity providers work with Basedash SSO and SCIM?

SSO works with any identity provider that supports SAML 2.0 or OIDC, including Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, Rippling, Ping Identity, and Auth0. SCIM provisioning follows the SCIM 2.0 standard and accepts the request formats Okta and Entra ID send, so those are the most common pairings. Other SCIM 2.0 clients work too, as long as they filter with a single equals condition, since Basedash doesn't support bulk operations, sorting, or ETags.

What does SCIM sync into Basedash?

SCIM syncs users, groups, and group memberships. For each user it carries the email address (the SCIM userName, which can't change after provisioning), first name, display name, job title, active status, and your directory's external ID. Groups are created, renamed, and deleted from the identity provider, and adding or removing someone there updates their Basedash membership. Roles and resource permissions aren't synced: provisioned people join as members, and admins decide in Basedash what each group can access.

How do directory groups map to permissions in Basedash?

Synced groups become Basedash groups, and an admin grants each one access. Data source grants decide who can query a source in chat, dashboards, exports, the SQL editor, and variables, and dashboards can be shared with specific groups. On Postgres, Basedash also passes the asker's groups to the database in the basedash.groups session variable, so row-level security policies filter what every AI answer can read. Customer-facing embeds are scoped by signed tokens instead, as described under embedding.

What happens when someone is offboarded in the identity provider?

When your identity provider deactivates or unassigns someone, it sends a SCIM request and Basedash deactivates their organization membership as soon as it arrives. They lose access to the organization's data, and their open chats are re-scoped right away, so timing depends only on how quickly your provider sends the change. Their dashboards, charts, and audit history stay in place for the team. A SCIM delete also deactivates instead of erasing, re-provisioning the same email restores the same membership, and the last active admin can't be deactivated.

Can we require everyone to sign in through SSO?

Yes. Once SSO is configured for a verified domain, everyone with an email address on that domain has to sign in or sign up through your identity provider. You add the domain in Settings, verify it with a DNS TXT record, and can let people with that domain join the organization automatically. Organizations that don't use SAML can instead require every member to sign in with Google.

Which plans include SSO and SCIM?

SSO and SCIM are part of the Enterprise plan, along with audit logs, and only organization admins can configure them. They're also included in self-hosted deployments, where SCIM uses the same endpoints at your own base URL with no extra environment variables. If SCIM requests return 403 Forbidden, the token is valid but the organization isn't on a plan that includes provisioning. See Enterprise for the rest of the plan, or self-hosting to run Basedash in your own infrastructure.

How do we connect Okta or Microsoft Entra ID over SCIM?

An organization admin opens Settings, then Security, and creates a named SCIM token. It starts with bd_scim_ and is shown only once, since Basedash stores just a hash. In Okta or Entra ID, create a SCIM 2.0 app, set the base URL to https://charts.basedash.com/scim/v2, and use the token as the bearer token. Test the connection, then assign the people and groups that need access. To rotate, create a new token, swap it in, test, and revoke the old one.

Connect your identity provider and let your directory decide who sees what.