How to Configure SSO/SCIM - Jumpcloud
Last updated: September 17, 2026
This guide explains how to integrate JumpCloud with Kula for enabling secure Single Sign-On (SSO) and user provisioning using SCIM.
Who can do this: Super Admin
Where to find it: Settings → Privacy, Compliance & Security → Security
SSO Integration with JumpCloud
Supported Features
SAML 2.0 integration
IdP-Initiated and SP-Initiated login support
Manual configuration without domain verification
Steps to Configure SSO in JumpCloud:
Add a New SAML Application:
Go to JumpCloud Admin Portal > SSO > Add New Application
Choose Custom SAML App
Set the Following Parameters:
SP Entity ID: Provided by Kula
ACS URL (Single Sign-On URL): Provided by Kula
IdP Entity ID: Use JumpCloud’s
SAML Subject: Email address
Download Metadata:
JumpCloud provides an XML or metadata URL
Upload Metadata to Kula:
In Kula, go to Settings → Privacy, Compliance & Security → Security, turn on SSO under Sign-in options, click Add SSO and select Jumpcloud
Upload the XML file or paste metadata values manually
Assign Users to the App
🔁 SCIM Provisioning with JumpCloud
JumpCloud’s SCIM support is currently more limited than Okta. If SCIM API integration is supported for your JumpCloud plan, follow these steps:
Enable SCIM in Kula:
Click Next: Setup SCIM at the end of the SSO setup in Kula (or edit your JumpCloud configuration later)
Copy the Authorization token from the SCIM configuration step
Configure JumpCloud (if SCIM is available):
Enter:
SCIM Base URL:
https://api.kula.ai/api/saml/scimBearer Token: The token from Kula
Contact JumpCloud support if SCIM is not directly available in your plan.
Good to know
Kula shows the values your identity provider needs. The Set up SSO step displays Kula's Assertion Consumer Service (ACS) URL and Service Provider (SP) Entity ID — copy them from there.
You can give Kula your identity provider's details three ways: upload the metadata XML, enter the metadata URL, or enter the SSO URL, Entity ID and X.509 certificate by hand.
SCIM is set up in the same place as SSO. After Set up SSO, click Next: Setup SCIM to get the SCIM connector base URL and authorization token, and turn on automatic provisioning.
At least one sign-in option must stay on. Kula won't let you turn off or delete the last one.
Turning off Email & password locks out external users. External collaborators such as agencies sign in with an email and password, so they lose access if you switch it off.
SCIM depends on your JumpCloud plan. If SCIM isn't available on your plan, SSO still works — you'll just add and remove users by hand.
FAQ
Where do I find the SCIM token?
In Kula, open Settings → Privacy, Compliance & Security → Security, edit your JumpCloud configuration and go to the SCIM configuration step. The Authorization token is shown there.
Can people still sign in with a password once SSO is on?
Yes, as long as Email & password stays turned on under Sign-in options. Turn it off to make everyone use SSO.
Will our agencies and other external users still be able to sign in?
Only if Email & password stays on. External users sign in with an email and password, not through your identity provider.
Why can't I turn off this sign-in option?
It's the only one still on. Turn on another sign-in option first — Kula always needs at least one.
Can we connect more than one identity provider?
Yes. Each one you add has its own toggle under Sign-in options.
Need help? If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.