Prerequisites
- A JumpCloud account with admin access
- A verified custom domain on your Auth application
Configure JumpCloud SAML
1
Create a custom SAML application in JumpCloud
- Log in to the JumpCloud Admin Portal
- Navigate to SSO Applications and click + Add New Application
- Choose Custom Application, then select Manage Single Sign-On (SSO) with Configure SSO with SAML
- On the SSO tab, enter temporary placeholders for now — you will replace them in a later step:
- SP Entity ID:
https://example.com - ACS URL:
https://example.com/acs
- SP Entity ID:
- Set SAMLSubject NameID to
emailand SAMLSubject NameID Format tourn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress - Under Attributes, add the user attributes you want in the assertion — typically
email,firstName, andlastName(these match Prelude’s default attribute mapping) - Click Save (and Continue to Application if prompted)
2
Export JumpCloud's IdP details
On the application’s SSO tab, collect the IdP values Prelude needs:
- IdP Entity ID — JumpCloud’s issuer, e.g.
https://sso.jumpcloud.com/saml2/${APP_ID} - IdP URL (SSO URL) — where Prelude sends SP-initiated requests
- IdP Certificate — click Export Metadata / download the certificate (PEM,
-----BEGIN CERTIFICATE-----)
3
Create the SAML connection in Prelude
Create the connection from JumpCloud’s IdP details. Start it disabled — you will enable it once the SP URLs are wired back into JumpCloud.
The response contains an
sp block with the values you need next:4
Paste the SP URLs back into JumpCloud
Return to the JumpCloud application’s SSO tab and edit the SAML settings:
- Set ACS URL to the
sp.acs_urlfrom the response - Set SP Entity ID to the
sp.entity_idfrom the response - Click Save
The values must match exactly — no trailing slash, and
https only.5
Assign users and enable the connection
- On the JumpCloud application’s User Groups tab, assign the groups who should have access.
- Enable the Prelude connection:
Rotating the IdP certificate
When JumpCloud rotates its signing certificate, update the connection’s IdP block (the Entity ID is immutable — to change it, delete and recreate the connection):Delete the connection
saml:<connection_id> user identifiers are retained so historical sessions stay auditable.