SSO and SCIM for Krisp Organizations: JumpCloud

Who can use this feature?

Plan: Call Center AI
Managed from: Krisp Admin Portal
User type: Admin
Other: IdP account admin privileges

Krisp Organizations support single sign-on (SSO) and SCIM user provisioning through your identity provider. This guide walks Admins through configuring SAML SSO with JumpCloud, sending group membership to Krisp, testing sign-in, enabling SCIM provisioning, and mapping your JumpCloud groups to Krisp teams.

Set this up in order: configure and verify SSO first, then enable SCIM provisioning, then map your teams. SCIM provisioning should be enabled only after SSO sign-in works.

  Hint

Setting up SSO and SCIM for a single team instead of an Organization? See Set up Krisp SSO and SCIM for a single team with JumpCloud.

Start the SSO setup in the Krisp Admin Portal

  1. In the Krisp Admin Portal, go to Settings >>> Policies >>> Set Org-level Single Sign-on (SSO) Policy.
  2. Click Set up SSO to open the Single Sign-On sidebar, and keep it open. You will copy values from it into JumpCloud, and paste JumpCloud values back into it later.

 

Add the Krisp application in JumpCloud

JumpCloud provides a pre-built Krisp application, so you do not need to create a custom SAML app.

  1. In JumpCloud, go to Access >>> SSO Applications >>> Add New Application.
  2. Search for Krisp, select it, and click Next.
  3. Enter a Display Label and, optionally, a Description. Turn Show this application in User Portal on or off depending on whether you want the app to appear in the JumpCloud User Portal.
  4. Click Save Application.
  5. On the Krisp was successfully added screen, click Configure Application.

Configure SAML in JumpCloud

On the SSO tab of the Krisp application, enter the following values:

JumpCloud field Value to enter (from Krisp)
IdP Entity ID The Your team slug value
SP Entity ID The Your team slug value
ACS URL The Reply URL (Assertion Consumer Service URL) value
Login URL The Single Sign-On URL value
IDP URL A unique ending for the URL, for example krispjumpcloud. You will copy the full URL back into Krisp later.

 

  Info

The IDP URL cannot be shared across applications, and it is not editable after the application is created.

Check the email attribute

Scroll down to the User Attributes section. Confirm that an attribute is present with Service Provider Attribute Name set to email and JumpCloud Attribute Name set to email. If it is not there, click Add Attribute and add it.

Send group membership to Krisp

Krisp maps your JumpCloud groups to Krisp teams, so the SAML assertion has to carry each user's group membership. This is configured in two places.

First, on each JumpCloud group:

  1. Go to Identity Management >>> Groups and open the group.
  2. In Group Details, scroll to Custom Attributes.
  3. Click on Add Custom Attribute >>> select String
  4. Set Attribute Name to groups.
  5. Click Save Group.

Then, on the Krisp application:

  1. Go to Access >>> SSO Applications >>> the Krisp application >>> SSO.
  2. Under Constant Attributes, click Add Attribute and set Service Provider Attribute Name to groups.
  3. Select the Include Group Attribute checkbox.
  4. Set Groups Attribute Name to groups.
  5. Click Save.

Download the certificate

On the Krisp application page, open the Actions menu and click Download Certificate. You will paste this certificate into Krisp in the next section.

Complete the SSO configuration in Krisp

Return to the Single Sign-On sidebar in the Krisp Admin Portal and fill in the following fields:

Krisp field Value to enter
Audience URI Your team slug
Identity provider single sign on URL The full URL shown below Login URL in JumpCloud
Identity provider issuer Your team slug
X-509 certificate The contents of the certificate you downloaded from JumpCloud

 

Click Done to save the configuration.

Assign users and groups in JumpCloud

  1. In JumpCloud, open the Krisp application and go to the User Groups tab.
  2. Select the groups that should be able to sign in to Krisp.
  3. Click Save.

Test sign-in and sync your IdP groups

Before you can map groups to Krisp teams, each group has to be synced to Krisp. This happens the first time a member of that group signs in.

  Important

On the first sign-in, a user needs to enter the team slug instead of their email address. Once that first sign-in completes, the user's IdP group is synced to Krisp and becomes available on the Mappings page, and signing in with the email address works as expected from then on.

Have one member of each group sign in before you continue, so every group you plan to map appears in Krisp.

Enable SCIM provisioning

SCIM lets JumpCloud automatically provision, update, and deactivate users in Krisp. It is recommended for Organizations managing large user bases.

  Important

Enable SCIM provisioning only after you have verified that SSO sign-in works.

  1. In the Krisp Admin Portal, go to Settings >>> Policies >>> Single Sign-On and open the Set up SSO sidebar.
  2. Turn on the SCIM Configuration toggle. The SCIM token and endpoint are generated as soon as you turn it on.
  3. In JumpCloud, open the Krisp application, go to the Provisioning tab, and click Configure.
  4. Under Configuration Settings, fill in:
    • Token Key: the SCIM token from Krisp
    • Base URL: the SCIM endpoint from Krisp
  5. Click Activate in JumpCloud.

Map Krisp teams to IdP groups

Once your groups have synced, assign them to the Krisp teams that should receive them.

  1. In the Krisp Admin Portal, go to Settings >>> Policies >>> Single Sign-On and click Manage mappings.
  2. Click Add team and add the Krisp teams you want to assign groups to.
  3. Click Assign IdP groups, then assign the relevant group to each team.

  Info

Your users do not need to accept invitations separately. Users who are not part of any IdP group appear under Ungrouped users.

Once users are provisioned into their mapped teams, each user needs to:

  • Install the Krisp app on their device.
  • Sign in with SSO by authenticating in JumpCloud.

Manage unmapped groups and users

If the Mappings page shows a warning about groups missing assignment, click Manage unmapped groups. Users from unmapped IdP groups do not have access to Krisp until their group is mapped to a team. From this view you can download a CSV of the affected addresses to check their details in JumpCloud, and assign or unassign IdP groups to manage your seats accordingly.

Set the Org-level SSO policy

When your configuration and team mappings are ready, set the policy on the Single Sign-On page. The policy applies only to the teams selected in SSO mapping. Depending on your selection:

  • Off: Org-level SSO becomes unavailable.
  • Enabled: users can authenticate with SSO, and email authentication remains available.
  • Enforced: all users, including Admins, must use SSO authentication only.

  Important

You can set the policy to Enforced only if at least one Org Admin is currently signed in via SSO. This prevents Admins from being locked out. Enabling Org-level SSO automatically disables team-level SSO for the mapped teams.

If SSO or SCIM errors occur

If sign-in or provisioning fails, collect the details below and send them to the Krisp team so we can investigate:

  • SSO sign-in errors: capture the SAML assertion. If your users see an error while signing in, also share a network log file that captures the error.
  • SCIM provisioning errors: share the error message shown in JumpCloud, along with any provisioning logs available for the time the error occurred.

Have more questions? Submit a request

Was this article helpful?
0 out of 0 found this helpful