Note: SAML integration is available for enterprise customers (see salto.io/pricing (https://www.salto.io/pricing)). To begin setup, contact support@salto.io.
Supported Features
- Identity provider (IdP)-initiated SSO - sign in to Salto by clicking the Salto tile in your JumpCloud User Console
- Service provider (SP)-initiated SSO - sign in by entering your email at https://app.salto.io
Before You Begin
Contact support@salto.io to request SAML setup. The setup has two phases: first you create the SSO application in JumpCloud and send us a few values; then Salto configures our side and sends you back a metadata URL to complete the connection.
Phase 1: Create the SSO Application in JumpCloud
Step 1: Add a custom SAML app
1. In the JumpCloud Admin Portal, go to User Authentication > SSO Applications
2. Click + Add New Application, select Custom SAML App, and click Next
3. Set the Display Label to "Salto"
Step 2: Configure the SSO tab
On the SSO tab, configure the following:
- SAMLSubject NameID: email
- SAMLSubject NameID Format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
- Signature Algorithm: RSA-SHA256
Step 3: Add attribute mappings
Under Attributes, add the following:
│ JumpCloud Attribute │ App Attribute │
│ email │ email │
│ firstName │ firstname │
│ lastName │ lastname │
Important: Make sure the email, first name, and last name fields are populated for all users who will sign in to Salto. If any of these fields are missing for a user, their sign-in will fail.
Step 4: Activate the app
Click Activate.
Note: The IdP URL becomes immutable after activation - if you ever need to change it, you will need to recreate the app.
Step 5: Copy your IdP values
From the SSO tab:
1. Copy the IdP URL
2. Click Actions > Download Certificate to download certificate.pem
What to Send to Salto
Email the following to support@salto.io, requesting SAML enablement:
1. The IdP URL (from Step 5)
2. The certificate.pem file (downloaded in Step 5)
3. The email domain(s) of the users who will sign in to Salto (e.g. acme.com)
Salto will configure our side and send you back a SAML metadata URL to complete the setup.
Phase 2: Complete the Connection
Once you receive the metadata URL from Salto:
Step 1: Upload the metadata
1. In your JumpCloud SSO application, open the SSO tab
2. Click Upload Metadata and provide the metadata URL you received from Salto - this automatically fills in the ACS URL and SP Entity ID
- If metadata upload isn't available, paste the ACS URL and SP Entity ID values Salto sent instead
3. Click Save
Step 2: Authorize your users
1. On the User Groups tab, authorize the JumpCloud groups that should have access to Salto
2. Click Save
Step 3: Test the connection
- IdP-initiated: click the Salto tile in your JumpCloud User Console - you should be taken directly into Salto
- SP-initiated (if requested): go to https://app.salto.io/login, enter your email address, and you will be redirected to your JumpCloud sign-in page
Let us know at support@salto.io whether the connection works, or share any errors you encounter.
Troubleshooting
If you encounter access denied errors or configuration problems, contact support@salto.io. Note that an organization admin must invite users to Salto; SSO users who have not been invited will not be able to access the platform. See Inviting members to your organization (https://help.salto.io/) for more details.
