Jumpcloud Self Serve SSO Steps - OIDC
On this page
The following steps have to be executed in the SingleStore Helios Portal and the JumpCloud Admin portal sequentially.
In the SingleStore Helios Portal
-
Open the ORG:your-org menu on the top and go to Organization Details.
-
Select the Authentication tab.
-
Use the Add Identity Provider list on the right to add a
SAML 2.
identity provider connection.0 -
Add a Connection Name, for example, JumpCloud OIDC.
In the JumpCloud Admin Portal
-
In the JumpCloud Admin console, select SSO under User Authentication.
-
Select Get Started or +Add New Application.
-
In the Create New Application Integration screen, scroll down to Custom Application, select it, and then select Next.
-
Select Manage Single Sign-On (SSO) then Configure SSO with OIDC and select
Next
. -
Fill in the details:
-
Display Label as SingleStore or SingleStore OIDC.
-
Select User Portal Image and upload a SingleStore icon, and select Next.
-
-
Proceed to Configure Application.
-
General Info should already be filled out by this point, so move on to the SSO tab.
-
Under Endpoint Configuration select Refresh Token such that both
Authorization Code
andRefresh Token
are selected. -
Under Client Authentication Type select
Public (None PKCE)
. -
Scroll down to Attribute Mapping (optional).
-
Select both
Email
andProfile
under Standard Scopes. -
From the SingleStore Helios Portal copy:
-
Login Redirect URLs to
Redirect URLs
-
Login Initiation URI.
to Login URL*.
-
-
Select User Groups at the top of the page.
-
Assign user(s) to the SingleStore application.
This can be all the users because SSO is an authentication, not authorization, and assigning users to the application does not grant them access to the SingleStore Helios Portal. -
Select Activate at the bottom of the page.
-
From the Application Saved popup, select Got It.
In the SingleStore Helios Portal
-
From the JumpCloud portal copy Client ID to Client ID .
-
Enter
https://oauth.
asid. jumpcloud. com/ Issuer
. -
Enter
https://oauth.
as Discovery Endpoint under Connection Settings.id. jumpcloud. com/. well-known/openid-configuration -
Adjust the scopes to be:
-
openid
(cannot edit) -
offline_
access -
email
-
profile
-
-
Add your domain, verify it and activate it.
Last modified: August 6, 2024