> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML with JumpCloud

> Configure SAML single sign-on to Gumloop with JumpCloud

This guide walks a JumpCloud administrator through connecting JumpCloud to Gumloop for SAML single sign-on.

## Before you start: get your SP details from Gumloop

A Gumloop organization admin generates an SSO setup link at [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso) (see [SSO, SAML & SCIM](/enterprise-features/sso_saml_scim)). The setup page shows the two Service Provider values you'll copy into JumpCloud:

* **Assertion Consumer Service (ACS) URL** — ends in `/acs`
* **SP Entity ID** — the same URL without the `/acs` suffix

The same page has the fields for the values JumpCloud produces: **Redirect URL**, **IDP Entity ID**, and the **Certificate** upload.

<Steps>
  ### Creating a JumpCloud application

  Start the JumpCloud set-up by creating an *Application*. From JumpCloud's admin console, click *SSO Applications* in the left navigation pane. This will take you to a new page — the precise page you see depends on how many existing connections the JumpCloud instance has.

  <Frame caption="Navigating to 'SSO Applications' in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud0.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=45a7c1dc4b311d1ca4999c66a333fe38" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud0.png" />
  </Frame>

  After clicking *SSO Applications*, you'll see a *Configured Applications* page listing any configured SSO apps. On this page, click the green *Add New Application* button toward the top left; it will route you to another new page.

  <Note>
    If you have no pre-existing SSO applications in JumpCloud, this page will show only a *Get Started* button. In this case, just click *Get Started*.
  </Note>

  <Frame caption="Adding a new application in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud1b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=b47dedf1ba2f24a4dca495ecadb58f3d" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud1b.png" />
  </Frame>

  By this point, you will have arrived at a page reading *Create New Application Integration* in the top left with several cards featuring the logos of common SaaS applications. Look for the *Custom Application* card in the lower right and click where it says *Select*. This will send you to a new page.

  <Frame caption="Choosing to create a 'custom application'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud2.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=8afc88d333daaef4576058f3fc895cf5" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud2.png" />
  </Frame>

  Upon arriving on this next page, click *Next* in the lower right to move on and see the next page.

  <Frame caption="Selecting 'Next' to move on">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud3.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=3ebc6d024ff31f3ef64055233370fe5d" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud3.png" />
  </Frame>

  Here, you'll see a few checkboxes. Select the first checkbox, labeled *Manage Single Sign-On (SSO)*. Checking this box will trigger two radio buttons to expand. Select the first option from the radio buttons: *Configure SSO with SAML*.

  <Frame caption="Choosing to configure the application with SAML SSO">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud4.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=4995f0c8d38ad95f376b2d4a4919a82a" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud4.png" />
  </Frame>

  Click *Next* in the lower right corner.

  <Frame caption="Selecting 'Next' to move on">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud4b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=5b43a82ba6193ba44b72d6104b800cef" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud4b.png" />
  </Frame>

  JumpCloud wants you to assign a *Display Label*. Write "Gumloop" here.

  <Frame caption="Setting a 'Display Label' in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud5.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=fb4558551104dc4407a622ab21a99239" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud5.png" />
  </Frame>

  Having entered a *Display Label*, click *Save Application* in the lower right corner. This will send you to a new page.

  <Frame caption="Saving the application to move on">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud5b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=025e625b8eebec8c6172d253fbf073a4" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud5b.png" />
  </Frame>

  On this page, press *Configure Application*.

  <Frame caption="Selecting 'Configure Application' to move on">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud6.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=96f35c137be158352b54223ce7a49968" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud6.png" />
  </Frame>

  You've now completed the first step of JumpCloud configuration and can move to the next step, entering details from Gumloop into JumpCloud.

  ### Enter Gumloop details in JumpCloud

  JumpCloud needs two important pieces of information from Gumloop.

  Start with the first of these, a field JumpCloud calls the *SP Entity ID*. Gumloop assigns this data the same name. From your Gumloop SSO setup page, copy the URL labeled *SP Entity ID* and paste it into JumpCloud's *SP Entity ID* field.

  <Frame caption="Inputting an 'SP Entity ID' in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud7.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=f66a0e36bfb3fef5a5d14c1bee70047b" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud7.png" />
  </Frame>

  JumpCloud asks for *ACS URLs*. Gumloop provides exactly one.

  Back on your Gumloop SSO setup page, you'll find a URL marked *Assertion Consumer Service (ACS) URL*. It looks nearly identical to the *SP Entity ID* from the previous step, only affixed with `/acs` at the end of the URL.

  Copy the *Assertion Consumer Service (ACS) URL* and paste it into JumpCloud as an *ACS URL*.

  <Frame caption="Pasting the ACS URL into JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud7b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=5dcfdf4814d8105ffe9c2e2a5efa0d38" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud7b.png" />
  </Frame>

  JumpCloud now has all the information it needs about Gumloop.

  ### Enter JumpCloud details in Gumloop

  The next step requires copying a few details from JumpCloud into Gumloop.

  First, scroll down to a URL that JumpCloud calls the *IDP URL*. Gumloop calls this the *Redirect URL*. Copy JumpCloud's *IDP URL* and paste it into your Gumloop SSO setup page as the *Redirect URL*.

  <Frame caption="Copying the JumpCloud 'IDP URL,' which will become the 'Redirect URL' in Gumloop">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud8.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=a19be8ce5ba0891179b38360a6aa133f" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud8.png" />
  </Frame>

  Gumloop also needs an *IDP Entity ID*. It turns out that JumpCloud doesn't provide one, but it's fine just to enter two matching strings in both JumpCloud and Gumloop.

  Write "JumpCloud" in Gumloop as the *IDP Entity ID*. You just need JumpCloud to match, so write "JumpCloud" in the field that JumpCloud calls *IDP Entity ID*.

  <Frame caption="Setting the 'IDP Entity ID' in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud8b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=afa3f6c1c90ab64af32efe6003364f85" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud8b.png" />
  </Frame>

  Next, you'll upload a *Certificate* in Gumloop. You'll find the file on the left side of the overlay you've been working in. Press *IDP Certificate Valid* > *Download Certificate*. JumpCloud creates a file called `certificate.pem`. Upload this file on your Gumloop SSO setup page as the *IDP Certificate*.

  <Frame caption="Finding the certificate.pem file in JumpCloud">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud8c.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=b2c909573992f3f776b28f3fdcb22c85" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud8c.png" />
  </Frame>

  You'll adjust one very important setting in JumpCloud before finishing up. Where JumpCloud writes *Sign*, change the radio button setting to *Assertion and Response*. JumpCloud's default setting will not work properly with Gumloop.

  <Frame caption="Instructing JumpCloud to sign both SAML assertions and responses">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud9.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=a35fe83b4926ffab0996b4b81dfbcc59" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud9.png" />
  </Frame>

  Hit *Save* in the bottom right corner.

  <Frame caption="Hitting 'Save' to finish the set-up">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/jumpcloud/jumpcloud8d.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=53eb75424e2bbb5d9d1236ad7001ae79" width="1920" height="1080" data-path="images/idp-guides/idp-assets/jumpcloud/jumpcloud8d.png" />
  </Frame>

  You've finished connecting Gumloop to JumpCloud. Please note, however, that a JumpCloud admin will need to assign users to the application before they can successfully sign in.
</Steps>
