Skip to main content

Configure authentication

Datagrok supports many authentication methods, including popular methods such as SSO and OAuth:

You can enable all methods separately or combined.

If supported authentication methods do not work for you, contact us on info@datagrok.ai, and we will discuss options for your specific case.

General (login-password) authentication​

General (login-password) authentication is the most basic method to authenticate users with Datagrok.

To configure login-password authentication:

  1. Go to the Settings > Users and Sessions. This section contains all authentication settings.
  2. To use the login-password method, enable 'Internal authentication' in General section
  3. To disable signup uncheck 'Signup Allowed' option
  4. To restrict from which domains people can sign up to the platform, use the 'Signup Domains Whitelist' option. You can set several domains separated with commas.
  5. To force people to use active emails, enable the 'Require Email Confirm' option.
  6. To require strong passwords (a mix of uppercase and lowercase letters, digits, or special characters, and a minimum length), enable 'Enforce Password Policy'.
  7. To show a message on the login form, for example a support contact, set 'Prompt'.
  8. To let people sign up through OpenID or SAML when they sign in for the first time, enable 'Allow Oauth Signup'. Otherwise, an administrator must create the user first.

For login-password authentication, it is important to configure an email service that will deliver signup, welcome, confirmation and forgot password emails.

Add users​

To create user:

  1. Go to Browse > Platform > Users.
  2. Click New and select New User.... The New User dialog opens.
  3. Enter the name, email, and login, and click OK.

For bulk provisioning, use the grok s CLI.

Use user groups to manage user permissions inside platform.

LDAP authentication​

Datagrok integrates with your LDAP or Active Directory server enabling the smooth domain authentication mechanism across all your services.

  1. Go to the Settings > Users and Sessions. This section contains all authentication settings.
  2. To use the LDAP method, enable 'Domain authentication'
  3. Enable 'Domain signup' to enable all users present on a domain controller to authenticate in the Datagrok platform. If the option is disabled, it is required to create the user in the Datagrok platform first to allow the user to log into the platform
  4. Configure LDAP server address/DNS name
  5. Set LDAP server port
  6. Enable LDAP SSL if you use LDAPS on your server
  7. Set LDAP Base DN. It should look like dc=datagrok,dc=ai.
  8. Set LDAP User DN. It should look like CN=USER-DATAGROK,OU=users,DC=datagrok,DC=ai
  9. Set LDAP User password

Note: To ensure only domain-managed users can access the platform:

  1. Disable 'Signup Allowed' to prevent unauthorized users from registering directly on Datagrok.
  2. Enable 'Signup Enabled' in 'Domain Authentication' to allow new users already registered in the organization's LDAP or Active Directory (AD) system to log in.
Sync AD groups with Datagrok groups

LDAP authentication lets AD users sign in with their domain credentials, but doesn't synchronize group membership. To keep Datagrok groups and shares in sync with AD groups, drive the platform from a script using the grok s CLI.

OpenID authentication​

This is the preferred and most powerful way to integrate with an external identity provider.
Datagrok supports the OpenID protocol to allow users to be authenticated using OpenID providers such as Azure AD, Google, Okta, Auth0, and any other OIDC-compliant identity provider.

  1. Go to the Datagrok Settings section Users and Sessions; this section contains all authentication settings.
  2. Enable Open Id authentication to use the OpenID method
  3. Get a well-known-configuration route and set it to 'Open Id Config Endpoint'. It should look like https://login.datagrok.ai/.well-known/openid-configuration. For Google, use https://accounts.google.com/.well-known/openid-configuration.
  4. Set Client Id as in your OpenID provider, and choose how Datagrok proves its identity to the provider in Secret Type:
    • Client Secret: Paste the client secret from the provider into Client Secret.
    • AzureAD JWT: Certificate-based authentication for Microsoft Entra ID (Azure AD). Generate a certificate and a private RSA key, paste them into Client Certificate and Client Private Key, and upload the certificate to your Entra ID application settings.
    • Signed JWT: Datagrok signs the client assertion with the server's signing key, and the provider verifies it against the keys the server publishes (JWKS). No secret is shared, and the key rotates with the server keys.
  5. Set Code Challenge Method (S256 by default, or None if your provider doesn't support PKCE).
  6. Set Scopes (openid profile email by default).
  7. Map the claims in the login token to the user's attributes: Login Claim (udn by default), Email Claim, First Name Claim, Last Name Claim, and Picture Claim. For Microsoft Entra ID, set Login Claim to preferred_username.
  8. Enable Auto Login using OpenID to forward users to authentication automatically without showing the login form.
  9. Make sure the correct Web Root is set in Admin section
  10. Enable Keep Token mode if you want to enable seamless integration with other services. Datagrok will request offline_access scope and keep encrypted external token in session metadata.

If users sign in through an identity-aware proxy and you need OpenID only for the OAuth flows of data connectors, turn off Use For Login.

Keep Token​

Default authentication token expiration is 1 hour for OpenID, and it only can be used for validating user identity.

To be able to use the token for accessing external services, enable Keep Token in OpenID settings.

When Keep Token is enabled, Datagrok requests offline access from the OpenID provider during authentication. This allows Datagrok to securely get a refresh token in addition to the access token.

Datagrok automatically refreshes the external OpenID token together with its own internal session token. Datagrok keeps a refresh token in the browser storage. Token refresh happens every 10 minutes and when a user session starts, ensuring uninterrupted user sessions and seamless integration with external services.

Datagrok applies different handling strategies depending on the token type, ensuring that server-side actions always require explicit user intent. If the external token is a JWT, the token signature is embedded into the Datagrok user token on the client side. The JWT payload is encrypted and stored in the database. Datagrok cannot perform external actions autonomously without token signature.

If the external token is opaque, the token is stored only inside the user JWT on the client side. The server never has direct access to the token contents.

That means, external tokens are never usable by the server without a user-initiated request

Long-lived sessions are supported without exposing privileged credentials, and Datagrok can integrate seamlessly with external systems while preserving user-controlled authorization boundaries.

Right now user OpenID authentication is supported by BigQuery and Databricks providers.

Group synchronization​

Datagrok can mirror the groups a user belongs to in your identity provider into Datagrok groups. Synchronization runs on every login: groups are matched by name, missing groups are created, and memberships the user no longer has on the provider side are removed. Groups created by the sync are owned by the Administrators role and are deleted when their last synced member leaves. Groups and memberships that an administrator created by hand are never removed, and roles such as Administrators are never matched.

To enable it, go to Settings > Users and Sessions > Group Sync and turn on Sync Groups (OpenID providers) or Sync Google Groups (Google Workspace).

OpenID providers​

With Sync Groups enabled, Datagrok reads the groups claim from the login token. Providers that put group names into that claim, such as Keycloak with a group membership mapper, need nothing else.

Microsoft Entra ID (Azure AD) does not put group names into tokens: cloud groups arrive as object IDs, and users with many groups get no claim at all. Datagrok then reads the user's transitive group membership from Microsoft Graph with the login access token. To set it up:

  1. In the app registration, add the delegated Microsoft Graph permissions User.Read and GroupMember.Read.All, and grant admin consent.
  2. In Datagrok, append GroupMember.Read.All to the OpenID Scopes, for example openid profile email GroupMember.Read.All.
  3. Set Login Claim to preferred_username. Entra ID tokens carry no udn claim.
  4. Use a configuration endpoint on login.microsoftonline.com. Other hosts are treated as generic OpenID providers, and only the token claim is read.

Every group the user belongs to becomes a Datagrok group, so a user in many groups creates many groups. Group display names must be unique in the tenant for matching to work.

Google Workspace​

Google tokens never carry group membership, so Datagrok reads it through the Cloud Identity API using a service account. This works with Google OpenID login and with IAP.

  1. Create a service account, enable domain-wide delegation for the scope https://www.googleapis.com/auth/cloud-identity.groups.readonly, and download its key JSON.
  2. In Datagrok, turn on Sync Google Groups, paste the key JSON into Google Group Service Account, and set Google Delegated Admin Email to a Workspace super-admin the service account impersonates.
note

Synchronization happens at login only. A user removed from a group keeps the Datagrok membership until the next login. When Keycloak synchronization is enabled on the server, login-time group sync is skipped.

SAML authentication​

  1. Go to Datagrok Settings section 'Users and Sessions'
  2. Enable SAML authentication
  3. Copy ACS URI and Entity ID to SAML provider (i.e. Google or Azure AD)
  4. Copy SSO URI to Datagrok as IdP Endpoint and Certificate. Make sure you switch to a multiline edit mode when copying certificate.
  5. Map the attributes the provider sends to the user's attributes: Email Claim, First Name Claim, and Last Name Claim (email, first_name, and last_name by default).

SAML doesn't synchronize group membership. To mirror directory groups, use the grok s CLI or switch to OpenID.

IAP authentication​

Datagrok supports Google Identity-Aware Proxy (IAP) out of the box. Configure Identity-Aware Proxy for Datagrok server for automatic login.

Datagrok automatically detects x-goog-iap-jwt-assertion header, validates the token using Google keys, and authenticates user.