Skip to main content

Signing In

SigmaShake authentication is browser-based. Running ssg auth login (or clicking Sign In on accounts.sigmashake.com) opens your browser to accounts.sigmashake.com, where you authenticate with an identity provider.

Signing in and downloading SigmaShake is always free. A paid subscription ($5/month — see sigmashake.com/pricing) is required to unlock governed value surfaces such as rule evaluation, the Hub, and Fleet. There is no free trial of those surfaces; access is gated on an active subscription from first use.

Supported sign-in providers​

ProviderNotes
GitHubOAuth — see what happens when you log in with GitHub below
GoogleOAuth
Microsoft (Azure AD / Entra ID)OAuth
AppleSign in with Apple
TwitchOAuth
Enterprise SSOSAML 2.0 or OIDC — see Enterprise SSO below

All five individual providers are fully supported, interchangeable sign-in methods on the accounts.sigmashake.com login page — pick whichever identity you already use. Twitch sign-in works the same way as the others: click Sign in with Twitch, authorize the app, and you land back in your account.

ssg auth login

In a terminal, this shows a menu. Select Browser (recommended) and pick your provider in the browser tab that opens.

What happens when you log in with GitHub​

  1. Bot check. A brief Cloudflare Turnstile challenge runs before you're redirected to GitHub (usually invisible).
  2. Authorize on GitHub. You approve the SigmaShake OAuth app, granting read access to your public profile and your primary verified email address.
  3. Account match or create.
    • Returning users are matched to their existing account by GitHub identity; your username and avatar are refreshed.
    • New users get an account created automatically from your GitHub username, avatar, and primary verified email.
  4. Session and license. SigmaShake signs you in and — if you have an active subscription — issues a license for your tier (Pro or Enterprise). Without a subscription you are signed in, but governed value surfaces stay locked until you subscribe.
  5. Redirect. You land back where you started, or on the accounts dashboard.

What SigmaShake receives: your GitHub username, avatar, and primary verified email address — nothing else. SigmaShake never sees your GitHub password, and this sign-in grant does not include write access to your repositories. Repository access is a separate, explicitly-authorized flow used only by ssg install when pulling .rules files from a private GitHub repo — see Installing from a Private GitHub Repo.

The other providers (Google, Microsoft, Apple, Twitch) follow the same shape: authorize, account match-or-create from your provider identity, session and license issued, redirect home.

Account linking​

Already signed in with one provider and want to add another? Start a new sign-in with action=link from your account settings (rather than the main login page) and SigmaShake merges the new identity into your existing account instead of creating a duplicate — your subscription, organizations, and settings all carry over. Manage linked identities from your account settings on accounts.sigmashake.com.

Enterprise SSO​

Enterprise subscribers can replace individual-provider sign-in with SAML 2.0 or OIDC single sign-on tied to their own identity provider (Okta, Azure AD, Google Workspace, or any standards-compliant IdP). Once configured, members use the same ssg auth login / accounts.sigmashake.com flow — sign-ins for your organization's domain are routed to your IdP.

See Fleet SSO Setup for OIDC/SAML configuration and the Okta setup guide for a full walkthrough.