Who can use this feature?
Plan: Call Center AI
Managed from: Krisp Admin Portal
User type: Admin
Other: IdP account admin privileges
Krisp Organizations support single sign-on (SSO) and SCIM user provisioning through your identity provider. This guide walks Admins through configuring SAML SSO with JumpCloud, sending group membership to Krisp, testing sign-in, enabling SCIM provisioning, and mapping your JumpCloud groups to Krisp teams.
Set this up in order: configure and verify SSO first, then enable SCIM provisioning, then map your teams. SCIM provisioning should be enabled only after SSO sign-in works.
Hint
Setting up SSO and SCIM for a single team instead of an Organization? See Set up Krisp SSO and SCIM for a single team with JumpCloud.
Start the SSO setup in the Krisp Admin Portal
- In the Krisp Admin Portal, go to Settings >>> Policies >>> Set Org-level Single Sign-on (SSO) Policy.
- Click Set up SSO to open the Single Sign-On sidebar, and keep it open. You will copy values from it into JumpCloud, and paste JumpCloud values back into it later.
Add the Krisp application in JumpCloud
JumpCloud provides a pre-built Krisp application, so you do not need to create a custom SAML app.
- In JumpCloud, go to Access >>> SSO Applications >>> Add New Application.
- Search for Krisp, select it, and click Next.
- Enter a Display Label and, optionally, a Description. Turn Show this application in User Portal on or off depending on whether you want the app to appear in the JumpCloud User Portal.
- Click Save Application.
- On the Krisp was successfully added screen, click Configure Application.
Configure SAML in JumpCloud
On the SSO tab of the Krisp application, enter the following values:
| JumpCloud field | Value to enter (from Krisp) |
|---|---|
| IdP Entity ID | The Your team slug value |
| SP Entity ID | The Your team slug value |
| ACS URL | The Reply URL (Assertion Consumer Service URL) value |
| Login URL | The Single Sign-On URL value |
| IDP URL | A unique ending for the URL, for example krispjumpcloud. You will copy the full URL back into Krisp later. |
Info
The IDP URL cannot be shared across applications, and it is not editable after the application is created.
Check the email attribute
Scroll down to the User Attributes section. Confirm that an attribute is present with Service Provider Attribute Name set to email and JumpCloud Attribute Name set to email. If it is not there, click Add Attribute and add it.
Send group membership to Krisp
Krisp maps your JumpCloud groups to Krisp teams, so the SAML assertion has to carry each user's group membership. This is configured in two places.
First, on each JumpCloud group:
- Go to Identity Management >>> Groups and open the group.
- In Group Details, scroll to Custom Attributes.
- Click on Add Custom Attribute >>> select String
- Set Attribute Name to groups.
- Click Save Group.
Then, on the Krisp application:
- Go to Access >>> SSO Applications >>> the Krisp application >>> SSO.
- Under Constant Attributes, click Add Attribute and set Service Provider Attribute Name to groups.
- Select the Include Group Attribute checkbox.
- Set Groups Attribute Name to groups.
- Click Save.
Download the certificate
On the Krisp application page, open the Actions menu and click Download Certificate. You will paste this certificate into Krisp in the next section.
Complete the SSO configuration in Krisp
Return to the Single Sign-On sidebar in the Krisp Admin Portal and fill in the following fields:
| Krisp field | Value to enter |
|---|---|
| Audience URI | Your team slug |
| Identity provider single sign on URL | The full URL shown below Login URL in JumpCloud |
| Identity provider issuer | Your team slug |
| X-509 certificate | The contents of the certificate you downloaded from JumpCloud |
Click Done to save the configuration.
Assign users and groups in JumpCloud
- In JumpCloud, open the Krisp application and go to the User Groups tab.
- Select the groups that should be able to sign in to Krisp.
- Click Save.
Test sign-in and sync your IdP groups
Before you can map groups to Krisp teams, each group has to be synced to Krisp. This happens the first time a member of that group signs in.
Important
On the first sign-in, a user needs to enter the team slug instead of their email address. Once that first sign-in completes, the user's IdP group is synced to Krisp and becomes available on the Mappings page, and signing in with the email address works as expected from then on.
Have one member of each group sign in before you continue, so every group you plan to map appears in Krisp.
Enable SCIM provisioning
SCIM lets JumpCloud automatically provision, update, and deactivate users in Krisp. It is recommended for Organizations managing large user bases.
Important
Enable SCIM provisioning only after you have verified that SSO sign-in works.
- In the Krisp Admin Portal, go to Settings >>> Policies >>> Single Sign-On and open the Set up SSO sidebar.
- Turn on the SCIM Configuration toggle. The SCIM token and endpoint are generated as soon as you turn it on.
- In JumpCloud, open the Krisp application, go to the Provisioning tab, and click Configure.
- Under Configuration Settings, fill in:
- Token Key: the SCIM token from Krisp
- Base URL: the SCIM endpoint from Krisp
- Click Activate in JumpCloud.
Map Krisp teams to IdP groups
Once your groups have synced, assign them to the Krisp teams that should receive them.
- In the Krisp Admin Portal, go to Settings >>> Policies >>> Single Sign-On and click Manage mappings.
- Click Add team and add the Krisp teams you want to assign groups to.
- Click Assign IdP groups, then assign the relevant group to each team.
Info
Your users do not need to accept invitations separately. Users who are not part of any IdP group appear under Ungrouped users.
Once users are provisioned into their mapped teams, each user needs to:
- Install the Krisp app on their device.
- Sign in with SSO by authenticating in JumpCloud.
Manage unmapped groups and users
If the Mappings page shows a warning about groups missing assignment, click Manage unmapped groups. Users from unmapped IdP groups do not have access to Krisp until their group is mapped to a team. From this view you can download a CSV of the affected addresses to check their details in JumpCloud, and assign or unassign IdP groups to manage your seats accordingly.
Set the Org-level SSO policy
When your configuration and team mappings are ready, set the policy on the Single Sign-On page. The policy applies only to the teams selected in SSO mapping. Depending on your selection:
- Off: Org-level SSO becomes unavailable.
- Enabled: users can authenticate with SSO, and email authentication remains available.
- Enforced: all users, including Admins, must use SSO authentication only.
Important
You can set the policy to Enforced only if at least one Org Admin is currently signed in via SSO. This prevents Admins from being locked out. Enabling Org-level SSO automatically disables team-level SSO for the mapped teams.
If SSO or SCIM errors occur
If sign-in or provisioning fails, collect the details below and send them to the Krisp team so we can investigate:
- SSO sign-in errors: capture the SAML assertion. If your users see an error while signing in, also share a network log file that captures the error.
- SCIM provisioning errors: share the error message shown in JumpCloud, along with any provisioning logs available for the time the error occurred.