# Set up SSO with JumpCloud

> Connect JumpCloud to Privatus Analytics with SAML 2.0 single sign-on: create the custom app, enter the SP entity ID and ACS URL, bind user groups and test.

1. In the JumpCloud Admin Portal go to **SSO Applications → Add New
   Application → Custom Application**, and choose **Manage Single Sign-On
   (SSO)** with **SAML 2.0**. Name it "Privatus Analytics".
2. On the **SSO** tab:

   | JumpCloud field | Value |
   |---|---|
   | IdP Entity ID | Any unique value, e.g. `jumpcloud-privatus` |
   | SP Entity ID | `https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_…` |
   | ACS URL | `https://privatusanalytics.com/users/auth/saml/callback` |
   | SAMLSubject NameID | email |
   | SAMLSubject NameID Format | `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress` |
   | Signature Algorithm | RSA-SHA256, sign Assertion |

   Optionally add an attribute `name` mapped to the user's full name.
3. Activate, then **Export Metadata** or copy the **IDP URL** and download
   the certificate.
4. In Privatus Analytics, **Workspace settings → SSO → SAML**: enter the
   IdP URL, the IdP entity ID and the certificate, list your email
   domains, and save.
5. In JumpCloud, bind **user groups** to the application.
6. **Test** in Privatus Analytics, then **Activate**.

JumpCloud supports SCIM for custom apps on some plans: see
[SCIM](/docs/teams/scim).
