Signing In
SigmaShake authentication is browser-based. Running ssg auth login (or clicking Sign In on accounts.sigmashake.com) opens your browser to accounts.sigmashake.com, where you authenticate with an identity provider.
Signing in and downloading SigmaShake is always free. A paid subscription ($5/month — see sigmashake.com/pricing) is required to unlock governed value surfaces such as rule evaluation, the Hub, and Fleet. There is no free trial of those surfaces; access is gated on an active subscription from first use.
Supported sign-in providers
| Provider | Notes |
|---|---|
| GitHub | OAuth — see what happens when you log in with GitHub below |
| OAuth | |
| Microsoft (Azure AD / Entra ID) | OAuth |
| Apple | Sign in with Apple |
| Twitch | OAuth |
| Enterprise SSO | SAML 2.0 or OIDC — see Enterprise SSO below |
All five individual providers are fully supported, interchangeable sign-in methods on the accounts.sigmashake.com login page — pick whichever identity you already use. Twitch sign-in works the same way as the others: click Sign in with Twitch, authorize the app, and you land back in your account.
ssg auth login
In a terminal, this shows a menu. Select Browser (recommended) and pick your provider in the browser tab that opens.
What happens when you log in with GitHub
- Bot check. A brief Cloudflare Turnstile challenge runs before you're redirected to GitHub (usually invisible).
- Authorize on GitHub. You approve the SigmaShake OAuth app, granting read access to your public profile and your primary verified email address.
- Account match or create.
- Returning users are matched to their existing account by GitHub identity; your username and avatar are refreshed.
- New users get an account created automatically from your GitHub username, avatar, and primary verified email.
- Session and license. SigmaShake signs you in and — if you have an active subscription — issues a license for your tier (Pro or Enterprise). Without a subscription you are signed in, but governed value surfaces stay locked until you subscribe.
- Redirect. You land back where you started, or on the accounts dashboard.
What SigmaShake receives: your GitHub username, avatar, and primary verified email address — nothing else. SigmaShake never sees your GitHub password, and this sign-in grant does not include write access to your repositories. Repository access is a separate, explicitly-authorized flow used only by ssg install when pulling .rules files from a private GitHub repo — see Installing from a Private GitHub Repo.
The other providers (Google, Microsoft, Apple, Twitch) follow the same shape: authorize, account match-or-create from your provider identity, session and license issued, redirect home.
Account linking
Already signed in with one provider and want to add another? Start a new sign-in with action=link from your account settings (rather than the main login page) and SigmaShake merges the new identity into your existing account instead of creating a duplicate — your subscription, organizations, and settings all carry over. Manage linked identities from your account settings on accounts.sigmashake.com.
Enterprise SSO
Enterprise subscribers can replace individual-provider sign-in with SAML 2.0 or OIDC single sign-on tied to their own identity provider (Okta, Azure AD, Google Workspace, or any standards-compliant IdP). Once configured, members use the same ssg auth login / accounts.sigmashake.com flow — sign-ins for your organization's domain are routed to your IdP.
See Fleet SSO Setup for OIDC/SAML configuration and the Okta setup guide for a full walkthrough.