# Single Sign-On SAML Integration - JumpCloud

If you have an Enterprise account in Row Zero, you can configure single sign-on (SSO) via [SAML 2.0](https://wiki.oasis-open.org/security/FrontPage#SAML_V2.0_Standard) using your organization's existing JumpCloud SSO provider. Row Zero supports SAML 2.0 for single sign-on with HTTP-POST binding.

Here is the information that you will need to configure a new Row Zero SAML application in JumpCloud:

1. In the JumpCloud console, click on the "**SSO Applications**" link in the left hand panel:  

   ![sso applications](https://cdn.sanity.io/images/2w8agf2t/production/4158b755310d9340df53319afd6ada5ad7c8a349-389x673.png)

2. Click on the "**+ Add New Application**" button towards the top left:  

   ![sso add new application](https://cdn.sanity.io/images/2w8agf2t/production/3c2ea1c59bad8fd196fa62f17f5fb097319ba049-634x286.png)

3. On the new "**Create New Application Integration**" screen, press the "**Select**" link under "**Customer Application**":  

   ![sso create new application](https://cdn.sanity.io/images/2w8agf2t/production/10c8825aeadc199aa6ecda9d56678b0193e8378b-1699x1138.png)

4. When prompted for "**Which application would you like to integrate?**", click the "**Next**" button in the bottom right hand corner:  

   ![sso application to integrate](https://cdn.sanity.io/images/2w8agf2t/production/644cfe79f7a72a2fe606f1a5709b65ef652fab0d-1909x1243.png)

5. When prompted for "**Select the features you would like to enable**", check "**Manage Single Sign-On (SSO)**", "**Configure SSO with SAML**", and "**Export users to this app (Identity Management)**"; then click "**Next**":  

   ![sso saml features](https://cdn.sanity.io/images/2w8agf2t/production/1c8c19859140fd47fd9cd42afbcf2fc39d202898-1899x1239.png)

6. When prompted for "**Enter general info**":
    - For **Display Label** type "Row Zero"
    - Click the **Logo** radio button
    - Dowload the Row Zero log by clicking [this link](https://d3gu6cpxmtctuo.cloudfront.net/brand/v2/rz-logo-black.png)
    - Click **Choose a File** and upload the Row Zero logo
    - Click the **Save Application** button  

      ![sso general information](https://cdn.sanity.io/images/2w8agf2t/production/3314f4a1d2b5d089e4d7b70a3c29e18b7a8b432d-1906x1240.png)

7. Once the Row Zero application was successfully added, click on the "**Configure Application**" button:  

   ![sso saml review](https://cdn.sanity.io/images/2w8agf2t/production/3ea2d2473f6af213e02e20ae9ff9e803605cd089-1911x1245.png)

8. On the "**SAML Single Sign-On**" page under the "**Configuration Settings**" section:
    - For **SP Entity ID** enter `urn:auth0:rowzero:<CONNECTION_NAME>`
        - **Note:** You will need to replace `CONNECTION_NAME` above with an identifier that Row Zero will provide. Contact us when you are setting up your SSO integration and we will give you the `CONNECTION_NAME` to use.
    - For **ACS URLs**, enter **Index** `0` and **Default URL** as `https://auth.rowzero.io/login/callback?connection=<CONNECTION_NAME>`
        - **Note:** Again, replace `CONNECTION_NAME` with the identifier Row Zero provides.
    - For **SAMLSubject NameID** select `email`
    - For **SAMLSubject NameID Format** select `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`
    - For **Signature Algorithm** select `RSA-SHA256`
    - For **Sign** select `Response`
    - For **Default RelayState** enter `https://rowzero.com/startlogin?connection=<CONNECTION_NAME>`
        - **Note:** Again, replace `CONNECTION_NAME` with the identifier Row Zero provides.  

          ![sso saml configuration settings](https://cdn.sanity.io/images/2w8agf2t/production/5eff77f39c379b0d2631eb32a9906ec7d7013160-1557x1617.png)

9. On the "**SAML Single Sign-On**" page under the "**Attributes**" section:
    - Under **User Attributes** click the **Add Attribute** button so two inputs are displayed and enter the following:
        - Enter `email` and `<USER_EMAIL_ATTRIBUTE>` (typically `email`, `user.email`, etc.)
        - Enter `name` and `<USER_DISPLAY_NAME_ATTRIBUTE>` (typeically `displayName`, `user.displayName`, etc.)
    - Under **Constant Attributes** enter the following:
        - Enter `email_verified` and **true**  

          ![sso saml attributes](https://cdn.sanity.io/images/2w8agf2t/production/e0b858b3ea3fdf8e1becc03727b0d853d8024fff-1515x763.png)

10. On the bottom right hand corner of the page, click the "**Save**" button:  

   ![sso saml save](https://cdn.sanity.io/images/2w8agf2t/production/b9759eb9fe2932522b68c5715247b60362fe1327-355x112.png)

11. Click on the "**User Groups**" tab and select any users or groups you wish to allow access to Row Zero and click the "**Save**" button.  

![sso saml users and groups](https://cdn.sanity.io/images/2w8agf2t/production/c1ca45073b5909b2d2a409f35fbfa56b8a93455e-1874x1311.png)

Once you have configured a Row Zero SAML application in JumpCloud, contact us at Row Zero so that we can finish configuring the SSO integration on our end.

This is the information that we will need from you:

1. Under the "**SSO**" tab in the "**Configuration Settings**" section, copy the "**Metadata URL**" and provide it to Row Zero:  

   ![sso metadata url](https://cdn.sanity.io/images/2w8agf2t/production/f186db244232a33f49b8bbc9b2a974b1ef966d7d-1297x520.png)

2. Under the "**SSO**" tab in the "**Configuration Settings** section, copy the "**Idp URL**" and provide it to Row Zero:  

![sso idp url](https://cdn.sanity.io/images/2w8agf2t/production/009f5b497adc5ce426117a4d3c118d4738b8c822-1300x511.png)
