---
title: "Sign In to Cobalt"
description: "Manage your account access. Sign in to the Cobalt app."
canonical_url: "https://docs.cobalt.io/articles/sign-in-to-cobalt-EGTXEey2h8"
md_url: "https://docs.cobalt.io/articles/sign-in-to-cobalt-EGTXEey2h8.md"
---
# Sign In to Cobalt

Manage your account access. Sign in to the Cobalt app.


:::info
**Learn about your first steps with Cobalt after receiving a welcome email.**

:::

## Set Up Your Account

Once you’ve received a welcome email from Cobalt, do the following:


1. Select **Sign In** in the email.
2. Create a strong password. To learn more, read our [password best practices](https://docs.cobalt.io/en-us/articles/password-best-practices-5wuZLWBn0e).

Once you’ve confirmed your email address and created a password, your Cobalt account is fully set up.

## Sign-in Methods

Depending on the configurations of your organization, you can sign in to Cobalt in the following ways:

* Through [SAML single sign-on](https://docs.cobalt.io/en-us/articles/sign-in-to-cobalt-EGTXEey2h8#h-saml-sso), if configured. Go to your identity provider system to sign in to Cobalt, or follow a unique URL.
  * If your organization has [enforced SAML](https://docs.cobalt.io/en-us/articles/configure-saml-sso-oT8Q3qO09D#h-enforce-saml-sso), authentication from the Cobalt [Sign In](https://app.us.cobalt.io/) page is not possible.
* From the Cobalt [Sign In](https://app.us.cobalt.io/) page, with:
  * Your email address and password.
  * Your Google account with which you were invited to Cobalt.     ![](https://docs.cobalt.io/api/attachments.redirect?id=67a5cfcd-32ad-4c9d-b0b5-f53147d1ff97)


:::tip
**Tip** If you have problems signing in, see [Troubleshoot Sign-in Issues](https://docs.cobalt.io/en-us/articles/troubleshoot-sign-in-issues-XLCGFWuPqk).

:::

## SAML SSO

We support [identity provider-initiated single sign-on (SSO)](https://docs.cobalt.io/en-us/articles/glossary-YfTMKeZ1VM#h-idp-initiated-sso) based on the [Security Assertion Markup Language](https://docs.cobalt.io/en-us/articles/glossary-YfTMKeZ1VM#h-security-assertion-markup-language) 2.0 (SAML 2.0) protocol. SAML-based SSO is available to all [PtaaS tiers](https://docs.cobalt.io/en-us/articles/cobalt-ptaas-tiers-tGUEyGwLaS).

Navigate to your identity provider, and select the Cobalt app to authenticate. Depending on the setup, you may need to follow a unique URL.

SAML SSO affects the following roles:

* [Organization Owner](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-owner)
* [Organization Member](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-member)
* [Pentest Team Member](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member)

If your organization [enforces SAML SSO](https://docs.cobalt.io/en-us/articles/configure-saml-sso-oT8Q3qO09D#h-enforce-saml-sso), **you must authenticate only through your identity provider**, such as Okta, OneLogin, or Microsoft Azure AD. Authentication from the Cobalt [Sign In](https://app.us.cobalt.io/) page is not possible.

Learn more about [configuring SAML SSO](https://docs.cobalt.io/en-us/articles/configure-saml-sso-oT8Q3qO09D) (for Organization Owners).


:::tip
**Tip** If you can’t sign in through SAML SSO, see our [troubleshooting tips](https://docs.cobalt.io/en-us/articles/troubleshoot-sign-in-issues-XLCGFWuPqk#h-cant-sign-in-using-saml-sso).

:::

## Two-Factor Authentication

We support two-factor authentication (2FA) **for users who sign in with their email and password**. If you’re using [SAML SSO](https://docs.cobalt.io/en-us/articles/sign-in-to-cobalt-EGTXEey2h8#h-saml-sso) to sign in, you don’t need to turn on 2FA.

* If your organization [enforces 2FA](https://docs.cobalt.io/en-us/articles/configure-organization-settings-AsPfjIf0Ht) for all users, configure it upon signing in.
* We recommend that you [enable 2FA](https://docs.cobalt.io/en-us/articles/account-settings-8tW4UtYkk3#h-two-factor-authentication) even if your organization doesn’t enforce it.


:::tip
**Tip** If you have problems signing in with 2FA, see our [troubleshooting tips](https://docs.cobalt.io/en-us/articles/troubleshoot-sign-in-issues-XLCGFWuPqk#h-problems-with-two-factor-authentication).

:::
