Prerequisites
- A JumpCloud account with admin access
- A verified custom domain on your Auth application
Configure JumpCloud SAML
1
Create a custom SAML application in JumpCloud
- Log in to the JumpCloud Admin Portal
- Navigate to SSO Applications and click + Add New Application
- Choose Custom Application, then select Manage Single Sign-On (SSO) with Configure SSO with SAML
- On the SSO tab, enter temporary placeholders for now. You will replace them in a later step:
- SP Entity ID:
https://example.com - ACS URL:
https://example.com/acs
- SP Entity ID:
- Set SAMLSubject NameID to
emailand SAMLSubject NameID Format tourn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress - Under Attributes, add the user attributes you want in the assertion, typically
email,firstName, andlastName(these match Prelude’s default attribute mapping) - Click Save (and Continue to Application if prompted)
2
Export JumpCloud's IdP details
On the application’s SSO tab, collect the IdP values Prelude needs:
- IdP Entity ID: JumpCloud’s issuer, e.g.
https://sso.jumpcloud.com/saml2/${APP_ID} - IdP URL (SSO URL): where Prelude sends SP-initiated requests
- IdP Certificate: click Export Metadata / download the certificate (PEM,
-----BEGIN CERTIFICATE-----)
3
Create the SAML connection in Prelude
Create the connection from JumpCloud’s IdP details. Start it disabled. You will enable it once the SP URLs are wired back into JumpCloud.
The response contains an
sp block with the values you need next:4
Paste the SP URLs back into JumpCloud
Return to the JumpCloud application’s SSO tab and edit the SAML settings:
- Set ACS URL to the
sp.acs_urlfrom the response - Set SP Entity ID to the
sp.entity_idfrom the response - Click Save
The values must match exactly, no trailing slash, and
https only.5
Assign users and enable the connection
- On the JumpCloud application’s User Groups tab, assign the groups who should have access.
- Enable the Prelude connection:
Rotating the IdP certificate
When JumpCloud rotates its signing certificate, update the connection’s IdP block (the Entity ID is immutable, to change it, delete and recreate the connection):Delete the connection
saml:<connection_id> user identifiers are retained so historical sessions stay auditable.