JumpCloud
Last Updated: August 06, 2026
An identity provider (IdP) uses an authentication token to vouch for a person's identity. Vasion Automate uses IdPs for several tasks, including logging in to the Admin Console and portals, deploying printers, releasing print jobs, and more.
If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.
Configure JumpCloud
To add an app integration for the Vasion Automate connection do the following:
- Create JumpCloud App
- Set Authentication Type
- Configure Single Sign On
- X509 Certificate
- Configure Provisioning
- Add PrinterLogic Admins
1. Create JumpCloud App
- In your preferred browser, go to your JumpCloud portal and log in.
- From the left-side menu, select Access.
-
Select SSO Applications.
- Select the + Add New Application button.
- Search for PrinterLogic, and select the PrinterLogic SaaS app.
- Select Next.
- In the Display Label field, name your app.
- (Optional): Add a description, and upload a logo.
- Select Save Application.
- Select Configure Application.
- Leave the current browser open on the new app screen for the following steps.
Leave the current browser on the new app page. To continue app configuration, open the Vasion Automate or PrinterLogic Admin Console in a new browser, and access the service provider information.
2. Set Authentication Type
In a separate browser window, log in to Vasion Automate, and do the following:
- Select Admin from the left-side navigation.
- Select the Authentication option.
-
Select the + New Authentication button.
- Select the IdP that you want to configure.
- Select Next.
- Give your IdP a unique name.
- (Optional) Add a description.
- Select SAML2 in the Authentication Protocol section.
-
In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the Just-in-Time (JIT) option deselected.
- Leave the IdP Information page open. You need this information for the next step.
3. Configure Single Sign On
- In the JumpCloud app, select the SSO tab.
-
Copy the URL below:
Copy Codehttps://jumpcloud.com/- Paste the URL in the JumpCloud IdP Entity ID field.
- Paste the URL in the Vasion Admin Console Issuer URL field.
- Copy the IdP Identifier from the Admin Console Service Provider Information section.
- Paste the IdP Identifier after the "/" in the JumpCloud IdP Entity ID field. For example, https://jumpcloud.com/<IdP Identifier>.
- Paste the IdP Identifier in the Admin Console Issuer ID field.
- Copy and paste the following from the Admin Console Service Provider Information section to the JumpCloud SSO tab:
- Copy the Admin Console Identifier (Entity ID), and paste it in the JumpCloud SP Entity ID field.
- Copy the Admin Console Reply Url (ACS), and paste it in the Default URL field in the JumpCloud ACS URLs section.
- Copy the Admin Console Relay State, and paste it in the JumpCloud Default RelayState field.
- In the JumpCloud Login URL field, replace the “YOUR_SUBDOMAIN” portion of the URL with your instance subdomain.
- Select the Declare Redirect Endpoint checkbox.
- Copy the JumpCloud IDP URL, and paste it in the Admin Console SSO URL field.
-
Scroll down to the JumpCloud Attributes section, and adjust mappings as needed.
For more information about the SSO Connector fields in JumpCloud, refer to SSO Application Connector Fields.
- Select Save in the JumpCloud app.
4. X509 Certificate
- Scroll up to the JumpCloud Metadata section in the app's SSO tab, and select the Export Metadata button.
- Open the XML file with a text editor, like Notepad++ .
- Remove the export content before and after the X509 Certificate.
-
Remove the export content before and after the X509 Certificate.
Ensure you are leaving only the X-509 certificate body from the text editor. This is the section between the <...X509Certificate> and <...X509Certificate> characters as shown in the image. The rest can be removed.
-
Add the following headers before and after the X509 Certificate content.
Copy Code-----BEGIN CERTIFICATE-----Copy Code-----END CERTIFICATE----- - Copy the X509 Certificate with the adjusted headers.
- Return to the Vasion IdP Information window and paste the certificate into the X509 Certificate field.
- Select Save in Vasion.
5. Configure Provisioning
Follow the steps in the dropdown related to your configuration (SCIM / JIT).
SCIM Provisioning
Configure SCIM
- Select the Identity Management tab in JumpCloud.
- Select Configure.
- Copy the Vasion SCIM Tenant URL and paste it into the JumpCloud Base URL field.
- Select the Generate New Token button in the Vasion SCIM Token section.
- Copy the SCIM Token and paste it into the JumpCloud Token Key field.
- Select Activate.
- Select Save.
Add User Groups
- Select the User Groups tab in JumpCloud.
- Search for and select the groups that you would like to bind to Vasion.
- Select Save.
Enable the IdP
JIT Provisioning
Enable the IdP
- In Vasion Automate, close the IdP Information page.
- In the Authentication page, select the button next to the configured IdP to turn it on.
JIT Provisioning Initial Login
When using JIT provisioning, the app creates users during the first sing-in attempt:
- Access your Vasion instance, and select Sign In With <IdP Name>.
- Attempt to sign in with your IdP credentials.
-
This sign-in attempt fails and returns you to the sign-in screen.
This behavior is expected. With JIT, this action triggers user creation in the Vasion instance.
- The second sign-in attempt with valid credentials initiates a typical sign-in sequence.
For admins who need access to the Admin Console, you still need to add them to the Users page located in Tools
Users.
6. Add PrinterLogic Admins
For steps on assigning users and roles to the PrinterLogic and Vasion Automate Admin Console, refer to Admin Console Users.
In this topic:









