Cubbie Conference December 10, 2026 in San Francisco Get tickets →

← Helpconnect your stack

Connect Okta, Google Workspace, Microsoft Entra ID, or JumpCloud

Connect Okta, Google Workspace, Microsoft Entra ID, or JumpCloud with read-only scopes to discover the software your team actually uses.

Supported identity providers

Cubbie connects to four identity providers to discover the software your team actually uses:

  • Okta
  • Google Workspace
  • Microsoft Entra ID
  • JumpCloud

What Cubbie reads

Connections are read-only. Cubbie requests only read scopes — for example, the Okta connection asks for okta.users.read, okta.apps.read, and okta.logs.read. With those scopes Cubbie reads:

  • The list of apps assigned in your identity provider
  • Active user counts and licensed seat counts per app
  • Last-activity timestamps

Cubbie never reads passwords, message content, or files, and it cannot change anything in your identity provider.

Connect a provider

1. Open Subscriptions in your dashboard and find the Integration connectors section.

2. Choose your provider. Okta asks for your Okta domain (for example https://acme.okta.com); Google Workspace asks for your customer ID.

3. Approve the consent screen in your identity provider using an admin account.

4. Run a sync. Discovered apps flow into your subscription registry, where you confirm or correct them.

Sync status and history

Each connection shows its status (connected, error, or revoked) and the result of the most recent sync, so expired credentials and partial syncs are easy to spot.

Disconnect or revoke

From the same Integration connectors section, use Disconnect on a connection to revoke access. Cubbie stops syncing immediately. Registry records that were already imported stay — they are your data — but usage signals stop updating. You can reconnect the same provider later without starting over.

Looking for SSO login instead?

This article covers stack discovery. If you want your team to sign in to Cubbie itself through your identity provider, see the SAML SSO and SCIM article instead — that is a separate setup under your buyer org settings.

Was this helpful?
Related