Users whose email domain matches the connection sign in through their JumpCloud directory. MFA, session length, and lifecycle stay on JumpCloud.
Open the connection
In the Authdog console:
- Select the project and environment.
- Open Authentication > Providers with the Enterprise filter.
- Choose JumpCloud.
- Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
- In JumpCloud, create a SAML application and paste those values exactly. Use the ACS URL as the ACS / Reply URL.
Send JumpCloud's values back
Provide Authdog with:
| Field | Value |
|---|---|
| Connection name | A name that shows in the Configured list |
| IdP SSO URL | The SSO URL from the JumpCloud application |
| IdP X.509 Certificate | The signing certificate, including the BEGIN and END lines |
You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select Fetch or Parse & autofill. It does not refresh itself later. Re-import when JumpCloud rotates the certificate.
Prefer RSA-SHA256 and SHA-256 if you turn on request signing.
Route by email domain
In Email domains (for SSO discovery), enter one or more domains separated by commas:
acme.com, eu.acme.comAn entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.
Test it
- Use the connection's Test action.
- Complete an SP-initiated sign-in.
- Confirm JumpCloud sends a stable subject and an email claim.
- Repeat in production with production URLs. A custom domain change can change the callback. Update JumpCloud with the URL currently shown in the form.
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | SAML fields, domain routing, and certificate rotation |
| SAML 2.0 | The same form for an IdP that is not a named vendor |
| Marketplace | The listing for this integration |