Managing SSO Identities in HCP Terraform
Introduction
This guide provides steps to resolve common Single Sign-On (SSO) issues in HCP Terraform, such as organizations not being visible, failed sign-in attempts, or login loops. The goal is to reset a user's SSO identity to restore access to an SSO-enabled organization.
Prerequisites
- Access to an HCP account.
- Access to an HCP Terraform account.
Procedure
Follow these steps to remove and reset SSO identities from your HCP Terraform account.
- Open a new private or incognito browser window and navigate to the HCP Terraform login page.
- Log in using your standard HCP Terraform username and password, not the SSO option.
- After logging in, do not select an organization if prompted.
- Navigate to your user settings by clicking your avatar in the top right and selecting Account settings.
- Select the SSO Identities tab.
- For each identity listed, click the
...menu and select the option to remove it. - After removing all SSO identities, log out of your HCP Terraform account.
- Attempt to log in again using your organization's SSO provider.
Further Troubleshooting
If the procedure above does not resolve the issue, consider the following steps.
Unlink HCP and HCP Terraform Accounts
Your user account may need to be unlinked from an HCP account to fully reset the identity association.
Check for Duplicate Accounts
It is possible that the SSO identity is associated with a different HCP Terraform or HCP account, such as one linked to a personal email address. If you have other accounts, repeat the main procedure for each of them to ensure all conflicting SSO identities are removed.