Costfluent Docs
  • Documentation
  • Guides
  • API Reference
Get started
Concepts
Connect a source
Reporting
Allocation
Planning
Optimization
Administration
    Organization and workspacesUsers, teams and rolesSign-in and securityAudit log
Developers
Administration

Sign-in and security

Each person chooses how they sign in, and an organization Owner can connect the company's identity provider so that people at your email domain sign in through it.

Before you start

  • Passkeys and connected accounts are personal: open the account menu, then Security.
  • Single sign-on needs the Owner organization role.

Available on the Scale plan. Compare plans

Sign-in methods

The sign-in page offers:

  • Email address and Password;
  • Sign in with a passkey;
  • Sign in with GitHub or Google, where the deployment offers them.

Add a passkey

  1. Open Security and, under Passkeys, select Add passkey.
  2. Enter a Device name, then confirm with your fingerprint, face or device PIN.

Each passkey shows when it was added and last used. Remove stops it working on that device. A browser without passkey support says so.

Connected accounts

Connected accounts lists the GitHub or Google accounts you can sign in with. Disconnect removes one. If it is the only way you can sign in, Costfluent refuses until you set a password or add a passkey.

Connect single sign-on

Open Settings, then Single sign-on.

  1. Under Connect an identity provider, enter the Email domain whose people should sign in through your provider.
  2. From your provider, enter the Discovery URL (the OpenID Connect discovery document, usually ending in /.well-known/openid-configuration), the Client ID and the Client secret. The secret is stored in a secret store and never shown again.
  3. Choose the Default role for people Costfluent creates: Viewer or Editor. Owner cannot be granted this way.
  4. Turn on Create accounts automatically if a person signing in for the first time should get an account at the default role.
  5. Select Save connection.

Verify the domain

  1. Select Show the TXT record and publish it in your domain's DNS.
  2. Select Verify domain. If the record is not found yet, wait for DNS to propagate and try again.

Enable and enforce

  • Enabled lets people at the domain sign in through your provider.
  • Require single sign-on makes everyone sign in through it. Every other session is ended, except those of break-glass Owners, and the product says how many sessions ended.

Remove connection sends people at the domain back to signing in with a password.

Related

  • Users, teams and roles
  • Audit log
Last modified on September 30, 2026
Users, teams and rolesAudit log
On this page
  • Before you start
  • Sign-in methods
  • Add a passkey
  • Connected accounts
  • Connect single sign-on
  • Verify the domain
  • Enable and enforce
  • Related