Skip to main content

Integrate with BambooHR

Integrate BambooHR with your JumpCloud account to seamlessly manage and onboard new employees by automatically importing and updating users and their attributes to JumpCloud. This helps limit manual overhead for HR and IT organizations, reduces input error and in combination with the Single Sign On (SSO) with BambooHR SAML connector, JumpCloud provides access to all employee resources through a single set of credentials.

Prerequisites

  • A JumpCloud administrator account
  • JumpCloud SSO Package or higher or SSO à la carte option
  • A Full Admin account and BambooHR “advantage” package at minimum
  • Your BambooHR tenant
  • Review BambooHR's JumpCloud Integration article

Important Considerations

  • Email BambooHR Support to enable the JumpCloud integration on your account.
  • Configuring JumpCloud SSO for BambooHR is recommended, but not required.
    • JumpCloud won’t manage or consume the BambooHR password. Setting up SSO with the BambooHR User Portal will let your Users access the Bamboo portal using their JumpCloud credentials.
    • JumpCloud managed users must have an email address that corresponds to an email address associated with a BambooHR account.
  • BambooHR will be the identity source once the SCIM integration is configured and serves as the “master” for user attributes. Once that identity is in JumpCloud, admins can manage access, authentication, and extend that identity to all JumpCloud managed resources.
  • The SCIM integration is managed by BambooHR. Please contact BambooHR Support for support.
  • The SCIM integration only sends employee records - user records not sent.
  • The SCIM integration is one-way - the employee identities are sent from BambooHR to JumpCloud.
  • Bamboo sends both active and inactive employee records. JumpCloud has logic implemented that will prevent inactive users being created in JumpCloud.
  • We strongly recommend setting Stagedas the user default for Manual / Single User APIinSettings > User Management > Default User State for User Creation in JumpCloud. See Manage User States to learn more.
    • You can easily identify new users created by the integration.
    • You can assign resources without granting access before the user's start date.
    • You can control whether or not an email is sent to the user when they are activated.
    • You can activate the user by changing their user state.
  • A user created by this integration will:
    • Be created in the user state specified for Default User State for User Creationfor Manual / Single User API.
    • Have a pending password status.
    • Need to establish and maintain their password within JumpCloud.
  • Users created in the Active user state won’t automatically be sent an activation email upon creation.
  • Updates to the user attributes specified in the settings for the JumpCloud app BambooHR will be synced to JumpCloud as long as the integration is active.
  • Group import isn’t supported.
  • An employee record in BambooHR must have a company email address for the information to be sent to JumpCloud.
Important
  • When you delete a BambooHR managed user in JumpCloud, that user still exists and has a work email address in BambooHR, the user will be recreated in JumpCloud
  • When you suspend a user in JumpCloud and the user is still active in BambooHR, the user state for that user will updated and set back to Active in JumpCloud
  • When you add a user in JumpCloud, the user won’t be created in BambooHR
  • When you do a manual sync from BambooHR to JumpCloud, a full sync is done, meaning all employee records, both active and inactive users are sent
  • When you make any changes to the settings for the JumpCloud application in BambooHR, a full sync is done, meaning all employee records, both active and inactive users are sent
  • There are other triggers that result in a full sync. Please contact BambooHR Support for more information

Attribute Considerations

  • Any attributes that have been selected within BambooHR for export to JumpCloud will overwrite values existing in JumpCloud with each update that is triggered in BambooHR.
    • It's recommended to Enable read-only on the user’s portal profile page for all users in the Organization Settings to prevent users and administrators from updating attributes in JumpCloud.

Creating a new JumpCloud Application Integration

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access> SSO Applications.
  2. Click + Add New Application.
  3. You can also enter the name of the application in the Search field and select it.
  4. You can either select an application from the available list or select Custom Application, and click Next.
  5. Select the required options from the Select Options page and click Next. The Enter General Info page is displayed.
  6. On the Enter General Info page, you can customize the display label, description and how the application displays:
    • Description - add a description that users will see in their user portal
    • User Portal Image - choose Logoor Color Indicator
    • Show in User Portal - select to ensure the app is visible in the user portal
  7. Optionally, expand the Advanced Settings section and customize the IdP URL:
    • Enter a custom value to replace the default application name in the SSO IdP URL endpoint ( https://sso.jumpcloud.com/saml2/{custom_value})
warning

The SSO IdP URL is not editable after the application is created. If you need to change this URL later, you must delete and recreate the connector.

  1. Click Save Application.
  2. Next, click:
    • Configure Application and go to the next section
    • Close to configure your new application at a later time
tip

Users are implicitly denied access to applications. See Authorize Users to an SSO Application.

note

Linking the Application to AI Gateway

  • The sections below walk through SSO configuration for this application. When that is complete, you can connect this application to JumpCloud AI Gateway so users can access its data from supported AI clients (for example, Cursor or ChatGPT).
  • Register the MCP server under Access > AI Gateway and link it to this application. The server appears under Servers in AI Gateway. When you open the application from Access > SSO Applications, the same server appears on the application's AI Gateway tab.
  • Not all applications support MCP. Confirm support with the application vendor or see Configure AI Gateway Integrations to learn more about supported integrations.

Configuring the SSO Integration

note

SSO is either on or off. There is not an option to allow users to either login with SSO or login with their BambooHR credentials.

To navigate to your JumpCloud SSO connector

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications.

  2. Create a new application or select it from the Configured Applications list.

  3. Select the SSO tab.

To configure JumpCloud

  1. In the ACS URL field, replace <YOURDOMAIN> with your account's registered BambooHR domain name.
  2. Optionally, configure:
MFA Claims
note

The Authentication Methods References (AMR) is automatically included in the SAML assertion by default. No additional configuration is required to enable this.

Complete the MFA Claim Configuration to define how the authentication context is sent in the SAML assertion.

  1. Under Auth Context, choose one of the following options based on your SP's requirements:
    • Send a single value for all successful MFA factors - select if the Service Provider accepts a generic confirmation for any MFA login. Enter the single URL or URN they accept
    • Send specific factors - select this option to map individual JumpCloud MFA methods to distinct values. In the Factor Mapping table, add each MFA factor enabled in your organization and enter the corresponding value required by the Service Provider
    • Send single value and specific factors - select to send both a generic identifier and specific factor details in the assertion
tip

Refer to your Service Provider's documentation to determine the specific URN or URL values required (e.g., Salesforce Session Security Levels). The values entered in this configuration must exactly match what the Service Provider expects.

MFA FactorService ProviderNotes
PasswordReference your Service Providers's documentation for the values they expect for each factor
TOTP
WebAuthN
Push NotificationJumpCloud Protect or other authenticator application
Duo Security
Device Trust
Device Trust + User VerificationJumpCloud Go (requires explicit configuration - see the next table)
API Key
External Identity Provider
MFA MethodMFA Value in AMR Claim
apikeyswk
duomfa
pwdpwd
totpotp
unk
wanhwk
pushmfa
uv
durthwk
durt_uvhwk
ext_idp

Learn more about MFA Claims.

Attributes

Configure User Attributes to be sent to the SP in assertions. User attributes are unique to each user. You can include attributes for standard user detail attributes or for custom attributes. For example, you can include standard attributes for users’ employee ID and department, or you can include a custom attribute for users’ application ID. Standard attributes are configured in the User Panel Details tab's User Information andEmployee Information sections.

Unlike user attributes, a Constant Attribute can be sent for every user in a specific group or application profile.

note

If required attributes are present, they are not editable.

  1. Under User Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • JumpCloud Attribute Name - select the corresponding attribute from the drop down list
  2. Repeat these steps for any desired user or custom attributes.
  3. Under Constant Attributes, click add attribute:
    • Service Provider Attribute Name - enter the service provider’s name for the attribute
    • Value - enter the corresponding attribute in JumpCloud
  4. Optionally, if groups are supported, select Include Group Attribute.

Learn More

  1. Select Save.

Download the certificate

  1. If you closed the application, find it in the Configured Applications list and click anywhere in the row to reopen its configuration window.
  2. Click Actions > Download Certificate.
tip

The certificate.pem will download to your local Downloads folder.

To configure BambooHR

  1. Log in to BambooHR as an administrator (This user's email should also be managed by JumpCloud).
  2. Select the Apps icon in the upper right.
  3. Scroll down to the Single Sign-On section, and select the SAML 2.0 icon.
  4. Select the Install button next to the SAML 2.0 icon.
  5. Enter the following information:
    • SSO Login URL - enter the JumpCloud IDP URL
    • x.509 Certificate - copy and paste the contents of the certificate downloaded in the previous section
  6. Optionally, select Allow optional email & password login.
Important

The "allow optional email & password login" enables employees to log in through [OneLogin/Microsoft/SAML/etc] or type in their email and password. Please note that while this is an option, it's recommend to leave this unchecked as installing a single sign-on option will disable the 2-Step Login in BambooHR.

  1. Select Install.

Authorizing SSO Application Access

Users are implicitly denied access to SSO Applications. After you connect an application to JumpCloud, you need to authorize user access to that application. You can authorize user access from the Applications, Users List or User Groups page.

To authorize user access from the SSO Application’s page

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Access > SSO Applications, then select the application to which you want to authorize user access.
  2. Select the User Groups tab. If you need to create a new group of users, see Get Started: User Groups.
  3. Select the check box next to the desired group of users to which you want to give access.
  4. Click Save.

To learn how to authorize user access from the Users or User Groups pages, see Authorize Users to an SSO Application.

Authorizing agent access

Agents are implicitly denied access to SSO applications. After you configure SCIM for a supported application, bind one or more agent groups on the application to grant agents access and start agent provisioning.

Agent access is managed through agent groups only. You cannot bind an individual agent directly to an application.

To authorize agent access from the SSO application page:

  1. In JumpCloud Admin Portal, go to Access > SSO Applications and select the application.
  2. Click the Agent Groups tab.
  3. Select the checkbox next to each agent group that should have access to the application.
  4. Click Save.

Agents in a bound agent group inherit access to the application. Removing an agent group removes access for the agents that inherited it through that group.

To authorize agent access from an agent group:

  1. In JumpCloud Admin Portal, go to Identity Management > Agent Groups and select the agent group you want to configure.
  2. Click the Applications tab.
  3. Select the application and click Save.
note

Only applications that support agent identities appear for assignment from an agent group. If an application does not support agents, it is not available on the Applications tab.

Validating SSO user authentication workflow(s)

Check your SP's documentation to ensure that both workflows are supported.

IdP-initiated user workflow

  • Access the JumpCloud User Console
  • Go to Applications and click an application tile to launch it
  • JumpCloud asserts the user's identity to the SP and is authenticated without the user having to log in to the application

SP-initiated user workflow

  • Go to the SP application login - generally, there is either a special link or an adaptive username field that detects the user is authenticated through SSO
note

This varies by SP.

  • Login redirects the user to JumpCloud where the user enters their JumpCloud credentials
  • After the user is logged in successfully, they are redirected back to the SP and automatically logged in
tip

See Additional User Experience Considerations when setting up JumpCloud SSO.

Configuring the SCIM Integration

To configure BambooHR 1

  1. Log in to your Bamboo administrator account.
  2. From the Home page, select the gear icon in the top right hand corner. This brings up your Settings page.
  3. Under your Account information, select Apps.
  4. On the next page, under Not Installed, scroll down to find JumpCloud, click Install.
  5. For the question: Which fields do you want to send to JumpCloud?*, determine the attributes you’d like to manage consistently in BambooHR and sync to JumpCloud.
  6. Keep this page open.
note

BambooHR will effectively master selected attributes in JumpCloud.

To get your JumpCloud API Key

note

The Admin API key needs to belong to an Admin that has one of the following roles; Manager, Administrator or Admin with Billing. Creating an administrator service account with one of these roles is one way to ensure the integration isn't dependent on a specific admin account.

warning

Once a new API key is generated, this revokes access to the current API key.

  1. Log in to the JumpCloud Admin Portal with the administrator account you want to use to generate the API key for this integration.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Click your initials in the bottom left corner.
  2. Select My API Key.
  3. Click Generate New API Key.
  4. Copy the API Key and store it securely, or leave this tab open while you complete the integration configuration steps in the SP.
Important

This is the only time your API key will be visible to you. Store it somewhere safe, such as the JumpCloud Password Manager, so you can access it later.

To configure BambooHR 2

  1. Back on your BambooHR page, in the JumpCloud Settings modal, paste the JumpCloud API Key under Add JumpCloud provided API Key*
  2. Click Install. You will receive a notification that JumpCloud was successfully installed.
  3. Your integration is now established. If you go back to your JumpCloud Administrator console, go to USER MANAGEMENT > Users and refresh the page, you will see newly added users.
    • If you set Staged as the default state, you can see a filtered view of just those users by clicking Staged option above the users list.
    • If you set Active as the default state, you can filter the All or Active view to just users with a password pending password status.

Provisioning Agents with SCIM

JumpCloud provisions agents and agent groups to supported SCIM applications using the same SCIM connection you configured for users. You do not create a separate SCIM connection for agents.

  • When an agent group is bound to a supported application, JumpCloud automatically creates, updates, and deprovisions agent accounts in that application based on the agent lifecycle in JumpCloud.

    • Agent group bound to the application: Agents in the group are provisioned when SCIM is active
    • Agent attribute changes: The downstream agent account is updated
    • Agent is suspended: The downstream account is set to inactive (active: false)
    • Agent is re-activated: The downstream account is re-enabled (active: true)
    • Agent group is unbound, or agent is removed from the group: The downstream account is deprovisioned
  • Agents and users are provisioned independently. An agent is never created, updated, or deleted through the user provisioning path.

  • There is no separate setting to turn agent provisioning on. If the application supports agents and an agent group is bound, agents in that group are provisioned automatically.

Group Management and agent groups

The Enable management of User Groups and Group Membership in this application setting on the Provisioning tab controls group push for both user groups and agent groups:

  • When group management is enabled, user groups and agent groups (for applications that support agent groups) provision as SCIM groups.
  • When group management is disabled, neither user groups nor agent groups are pushed as SCIM groups.
  • Individual agent account provisioning is not controlled by the group management setting. Agents in a bound agent group are provisioned as accounts regardless of whether group push is enabled.
note
  • Agent credentials, secrets, and tokens are never sent in a SCIM payload.
  • To stop provisioning agents to an application, unbind the agent groups from the application or delete the agents in JumpCloud.

Attribute Mappings

The following table lists attributes that BambooHR sends to JumpCloud. Any updates to the fields selected in the settings for the JumpCloud app will trigger an update to those values in JumpCloud with the exception of work extension.

JumpCloud AttributesSCIM AttributeNotes
Optional Mappings
company$enterpriseUser.organization
costCenter$enterpriseUser.costCenter
department$enterpriseUser.department
emailuserName
employeeIdentifier$enterpriseUser.employeeNumber
employeeTypeuserType
firstnamename.givenName
isAssignedToApp && !(jcUser.suspended == true)active
jobTitletitle
lastnamename.familyName
notNullOrEmpty(jcUser.displayname) ? jcUser.displayname : (notNullOrEmpty(jcUser.lastname) ? jcUser.firstname + ' ' + jcUser.lastname : jcUser.firstname)displayName
notNullOrEmpty(providerUser.externalId) ? providerUser.externalId : jcUser.idexternalId
notNullOrEmpty(providerUser.locale) ? providerUser.locale : 'en-US'locale
notNullOrEmpty(providerUser.preferredLanguage) ? providerUser.preferredLanguage : 'en-USpreferredLanguage
toScimAddresses(find(jcUser.addresses, .type == 'work') ?? first(jcUser.addressesaddresses
toScimEmails(jcUser.email)emails
toScimPhoneNumbers(find(jcUser.phoneNumbers, .type == 'work') ?? first(jcUser.phoneNumbers))phoneNumbers

Agent Attributes

On the Provisioning tab, the Agent Attributes section lists the default mappings JumpCloud sends when an agent is provisioned to this application.

Default Agent Attribute Mappings

JumpCloud AttributeSCIM AttributeNotes
Required Mappings
emailuserNameThe agent email is used as the username.
Optional Mappings
displaynamedisplayNameAgent display name.
notNullOrEmpty(providerAgent.externalId) ? providerAgent.externalId : jcAgent.idexternalIdExisting provider external ID, otherwise the JumpCloud agent ID.
isAssignedToApp && jcAgent.state == "ACTIVATED"activeActive only while the agent is bound to the application and in the ACTIVATED state.

To review or edit agent attribute mappings:

  1. Open the application and click the Provisioning tab.
  2. Expand Agent Attributes and click Edit.
  3. Review the Required Mappings and Optional Mappings tables.
  4. Click Preview mappings to review how an agent will appear in the target application.
  5. Click Save and Sync or Update.
  6. To revert to the defaults shown above, click Restore Defaults.

Agent Group Attributes

For applications that support agent groups, the Agent Group Attributes section lists the default mappings JumpCloud sends when an agent group is provisioned as a SCIM group.

Default Agent Group Attribute Mappings

JumpCloud AttributeSCIM AttributeNotes
Required Mappings
namedisplayNameAgent group name.
Optional Mappings
notNullOrEmpty(providerAgentGroup.externalId) ? providerAgentGroup.externalId : jcAgentGroup.idexternalIdExisting provider external ID, otherwise the JumpCloud agent group ID.
Group membershipmembersAdding or removing an agent from the group updates membership in the downstream SCIM group.

To review or edit agent group attribute mappings:

  1. Open the application and click the Provisioning tab.
  2. Confirm Enable management of User Groups and Group Membership in this application is selected if you want agent groups pushed as SCIM groups.
  3. Expand Agent Group Attributes and click Edit.
  4. Review or change mappings, then click Preview Mappings.
  5. Click Save and Sync or Update.

Removing the Integration

Removing the Integration
warning

These are steps for removing the integration in JumpCloud. Consult your SP's documentation for any additional steps needed (like disabling "mandatory SSO login" settings) to remove the integration in the SP. Failure to remove the integration successfully for both the SP and JumpCloud may result in users, including admins, losing access to the application.

Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

To deactivate the SCIM Integration

  1. Log in to the JumpCloud Admin Portal.

  2. Go to Access > SSO Applications.

  3. Search for the application that you’d like to deactivate and click to open the configuration window.

  4. Click Actions > Deactivate IdM and then click confirm.

To deactivate the SSO Integration

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > SSO Applications.
  3. Search for the application that you’d like to deactivate and click to open its details panel.
  4. Select the SSOtab.
  5. Scroll to the bottom of the configuration.
  6. Click Deactivate SSO.
  7. Click Save.
  8. If successful, you will receive a confirmation message.

To delete the application

  1. Log in to the JumpCloud Admin Portal.

  2. Go to Access > SSO Applications.

  3. Search for the application that you’d like to delete.

  4. Check the box next to the application to select it.

  5. Click Delete.

  6. Enter the number of the applications you are deleting

  7. Click Delete Application.

  8. If successful, you will see an application deletion confirmation notification.

Was this information helpful?