How to Configure SSO/SCIM - Jumpcloud

Last updated: September 17, 2026

This guide explains how to integrate JumpCloud with Kula for enabling secure Single Sign-On (SSO) and user provisioning using SCIM.

Who can do this: Super Admin

Where to find it: Settings → Privacy, Compliance & Security → Security

SSO Integration with JumpCloud

Supported Features

  • SAML 2.0 integration

  • IdP-Initiated and SP-Initiated login support

  • Manual configuration without domain verification

Steps to Configure SSO in JumpCloud:

  1. Add a New SAML Application:

    • Go to JumpCloud Admin Portal > SSO > Add New Application

    • Choose Custom SAML App

  2. Set the Following Parameters:

    • SP Entity ID: Provided by Kula

    • ACS URL (Single Sign-On URL): Provided by Kula

    • IdP Entity ID: Use JumpCloud’s

    • SAML Subject: Email address

  3. Download Metadata:

    • JumpCloud provides an XML or metadata URL

  4. Upload Metadata to Kula:

    •  In Kula, go to Settings → Privacy, Compliance & Security → Security, turn on SSO under Sign-in options, click Add SSO and select Jumpcloud

    • Upload the XML file or paste metadata values manually

  5. Assign Users to the App

🔁 SCIM Provisioning with JumpCloud

JumpCloud’s SCIM support is currently more limited than Okta. If SCIM API integration is supported for your JumpCloud plan, follow these steps:

  1. Enable SCIM in Kula:

    • Click Next: Setup SCIM at the end of the SSO setup in Kula (or edit your JumpCloud configuration later)

    • Copy the Authorization token from the SCIM configuration step

  2. Configure JumpCloud (if SCIM is available):

    • Enter:

      • SCIM Base URL: https://api.kula.ai/api/saml/scim

      • Bearer Token: The token from Kula

Contact JumpCloud support if SCIM is not directly available in your plan.

Good to know

  • Kula shows the values your identity provider needs. The Set up SSO step displays Kula's Assertion Consumer Service (ACS) URL and Service Provider (SP) Entity ID — copy them from there.

  • You can give Kula your identity provider's details three ways: upload the metadata XML, enter the metadata URL, or enter the SSO URL, Entity ID and X.509 certificate by hand.

  • SCIM is set up in the same place as SSO. After Set up SSO, click Next: Setup SCIM to get the SCIM connector base URL and authorization token, and turn on automatic provisioning.

  • At least one sign-in option must stay on. Kula won't let you turn off or delete the last one.

  • Turning off Email & password locks out external users. External collaborators such as agencies sign in with an email and password, so they lose access if you switch it off.

  • SCIM depends on your JumpCloud plan. If SCIM isn't available on your plan, SSO still works — you'll just add and remove users by hand.

FAQ

Where do I find the SCIM token?
In Kula, open Settings Privacy, Compliance & Security Security, edit your JumpCloud configuration and go to the SCIM configuration step. The Authorization token is shown there.

Can people still sign in with a password once SSO is on?
Yes, as long as Email & password stays turned on under Sign-in options. Turn it off to make everyone use SSO.

Will our agencies and other external users still be able to sign in?
Only if Email & password stays on. External users sign in with an email and password, not through your identity provider.

Why can't I turn off this sign-in option?
It's the only one still on. Turn on another sign-in option first — Kula always needs at least one.

Can we connect more than one identity provider?
Yes. Each one you add has its own toggle under Sign-in options.

Need help? If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.