JumpCloud
Connect JumpCloud to Ploy to bring your JumpCloud users, user groups and SSO applications into Ploy, and to let Ploy manage group membership and user accounts in JumpCloud.
What Ploy syncs from JumpCloud
Once connected, Ploy scans your JumpCloud tenant on a schedule and keeps the following up to date:
Users — every JumpCloud user becomes a person in Ploy with their profile attributes (name, email, department, job title, manager, employee ID, employment type, start and end dates, location and organisation). Ploy also records each user's login identity, whether the account is active, suspended or not yet activated, and whether MFA is configured.
User groups — each JumpCloud user group becomes a group resource in Ploy, with its members listed as access to that group. Ploy also records which applications each group is bound to.
Applications — each JumpCloud SSO application becomes an application resource in Ploy (active or archived, depending on whether SSO is active), and SSO applications with a recognisable web domain are added to your app inventory. Ploy records which users and which user groups are assigned to each application.
With the connection in place Ploy can also act on JumpCloud: add a user to or remove a user from a user group (for example from an access request or an access review), and create, update or delete JumpCloud user accounts from your automations.
Prerequisites
A JumpCloud administrator account. The API key you create inherits the permissions of the administrator who creates it, so use an account with at least read access to users, user groups and applications. If you want Ploy to change group membership or manage user accounts, the administrator needs write access too.
Your JumpCloud data-center region: US (
console.jumpcloud.com) or EU (console-eu.jumpcloud.com). Check the URL you use to sign in to the JumpCloud Admin Portal.
Step 1 — Create an API key in JumpCloud
Sign in to the JumpCloud Admin Portal.
Click your profile (top right) and choose My API Key.
Generate a new API key and copy it — you will paste it into Ploy in the next step.
If you set an expiry on the key, choose one that matches your company's risk tolerance and remember to generate a new key and update it in Ploy before it expires. A key that expires or is rotated in JumpCloud stops the Ploy sync until it is updated.
Keep the key somewhere safe; JumpCloud only shows it once.
Step 2 — Connect JumpCloud in Ploy
In Ploy, go to Integrations, find JumpCloud and click Connect.
Enter your JumpCloud API Key — paste the key you created in Step 1. This field is required.
Select your data center region — choose US (console.jumpcloud.com) or EU (console-eu.jumpcloud.com). This field is required and defaults to US. If your organisation is hosted in JumpCloud's EU data center you must switch it to EU; otherwise Ploy will call the US console and the connection test will fail.
Click Test to check the connection, then Save. Ploy verifies the key by reading one user from your JumpCloud tenant.
After saving, the first scan starts automatically. Depending on the size of your tenant it can take a little while for all users, groups and applications to appear in Ploy.
Updating the API key
If you rotate the key in JumpCloud, open the JumpCloud integration in Ploy again, paste the new key into Enter your JumpCloud API Key, test and save. You do not need to re-select the region unless it has changed.
Troubleshooting
"Invalid API key" — the key was rejected by JumpCloud. Check it was copied in full, has not expired or been revoked, and that you selected the correct data-center region (a key from one region is not accepted by the other console).
"API key does not have sufficient permissions" — the administrator who created the key does not have enough access. Create the key from an administrator account with read access to users, groups and applications (and write access if you want Ploy to manage groups or users).
"API endpoint not found - check base URL" — the selected region could not serve the request. Re-check whether your tenant is on
console.jumpcloud.com(US) orconsole-eu.jumpcloud.com(EU)."Failed to connect to JumpCloud" — a temporary network or JumpCloud error. Try the test again in a few minutes; if it keeps failing, contact Ploy support.
Users, groups or applications are missing after the first scan — scans run in the background and can take a while on large tenants. If data is still missing after an hour, confirm the API key's administrator can see the missing objects in the JumpCloud Admin Portal.