Who can use this feature?
Plan: Call Center AI
Managed from: Krisp Admin Portal
User type: Admin
Other: IdP account admin privileges
This article describes how to set up single sign-on (SSO) and SCIM user provisioning for a single Krisp team using JumpCloud. SSO lets your users log in with your company credentials, and SCIM keeps team membership in sync with your identity provider (IdP). Krisp SSO is based on SAML 2.0.
Set this up in order: configure and verify SSO first, then enable SCIM provisioning. SCIM should be enabled only after SSO sign-in works.
Hint
For a general overview of Krisp SSO, see Getting started with Krisp SSO.
Open your Krisp SSO settings
In your Admin Portal, go to Settings >>> Team Settings, then open Security >>> Authentication. Turn on the Enable SSO toggle and click SAML to open the SAML panel.
You will copy values from this panel into JumpCloud, and paste JumpCloud values back into it later. This article refers to it as your Krisp Settings. Keep the panel open while you work in JumpCloud.
Configure JumpCloud for SSO
JumpCloud provides a pre-built Krisp application, so you do not need to create a custom SAML app.
Add the Krisp application
- In JumpCloud, go to Access >>> SSO Applications >>> Add New Application.
- Search for Krisp, select it, and click Next.
- Enter a Display Label and, optionally, a Description. Turn Show this application in User Portal on or off depending on whether you want the app to appear in the JumpCloud User Portal.
- Click Save Application.
- On the Krisp was successfully added screen, click Configure Application.
Fill in the SAML settings
On the SSO tab of the application, enter the following values:
| JumpCloud field | Value to enter |
|---|---|
| IdP Entity ID | The Your team slug value from Krisp Settings |
| SP Entity ID | The Your team slug value from Krisp Settings |
| ACS URL | The Reply URL (Assertion Consumer Service URL) value from Krisp Settings |
| Login URL | The Single sign on URL value from Krisp Settings |
| IDP URL | A unique ending for the URL, for example krispjumpcloud. You will copy the full URL back into Krisp Settings later. |
Info
The IDP URL cannot be shared across applications, and it is not editable after the application is created.
Add the email attribute
Stay on the same page and scroll down to the Attributes section. If the attribute is not there already, click add attribute and enter:
- Service Provider Attribute Name: email
- JumpCloud Attribute Name: email
Save the changes.
Download the certificate
On the application page, open the Actions menu and click Download Certificate. You will paste this certificate into Krisp in the next section.
Complete the SSO setup in Krisp
Return to your Krisp Settings and fill in the following:
- Copy the Your team slug value into the Audience URI and Identity provider issuer fields. These must match the SP Entity ID and IdP Entity ID values you entered in JumpCloud.
- Open the downloaded certificate in a text editor and copy its contents into the X-509 certificate field.
- In JumpCloud, copy the full URL shown below the Login URL field, then paste it into the Identity provider single sign on URL field in Krisp Settings.
- Click Configure.
Assign users and groups
- In JumpCloud, open the Krisp application and go to the User Groups tab.
- Select the users and groups that should be able to sign in to your Krisp team.
- Click save.
The assigned users can now sign in to Krisp using your team slug and authenticate through JumpCloud. Test sign-in with one or two accounts before rolling SSO out more widely.
Info
On the first sign-in, a user may need to enter the team slug instead of their email address. Once that first sign-in completes, signing in with the email address works as expected.
Notes and limitations
- The team slug is modifiable, but it must be unique.
- If you belong to multiple Krisp teams with SSO, you cannot use your email instead of the team slug during sign-in.
- You can turn on Enforce SSO only if you, as an Admin, are currently signed in via SSO.
Enable SCIM provisioning
SCIM lets JumpCloud automatically provision, update, and deactivate users in Krisp. It is recommended for teams managing large user bases.
Important
Enable SCIM provisioning only after you have verified that SSO sign-in works.
- In your Krisp Admin Portal, go to Settings >>> Team Settings >>> Security >>> Authentication and click SCIM to open the SCIM panel.
- Turn on the Enable SCIM toggle. The setting is saved as soon as you turn the toggle on.
- In JumpCloud, open the Krisp application, go to the Provisioning tab, and click Configure.
- Under Configuration Settings, fill in:
- Token Key: the SCIM token from Krisp
- Base URL: the SCIM endpoint from Krisp
- Click Activate in JumpCloud.
Manage users through SCIM
Once SCIM is active, add users to the groups assigned to the Krisp application in JumpCloud. They are provisioned into your Krisp team and take up the available unassigned seats. To unassign a user, remove them from the Krisp application (or the relevant group) or from your JumpCloud account.
Hint
While SCIM is enabled, you cannot assign or unassign users from the Krisp team dashboard. Manage membership from JumpCloud.
Your users do not need to accept an invitation. The only thing they need to do is:
- Install the Krisp app on their device.
- Use the Sign in with SSO flow after landing on account.krisp.ai, then authenticate via JumpCloud.
If SSO or SCIM errors occur
If sign-in or provisioning fails, collect the details below and send them to the Krisp team so we can investigate:
- SSO sign-in errors: capture the SAML assertion. If your users see an error while signing in, also share a network log file that captures the error.
- SCIM provisioning errors: share the error message shown in JumpCloud, along with any provisioning logs available for the time the error occurred.