The following steps will lead you through the process of setting up single sign-on through JumpCloud. You will use the Admin JumpCloud Portal to add an application and copy the metadata URL into Tesorio. This will allow all authorized users at your company to use JumpCloud for accessing Tesorio.
Step 1
To configure JumpCloud
Log in to the JumpCloud Admin Portal.
Navigate to User Authentication > SSO Applications.
Select + Add New Application
Click Select on the Custom Application
Click Next.
Note:
If you search for and select Custom SAML app, SSO features are pre-selected.
Select Manage Single Sign-On (SSO), select either the Configure SSO with SAML and click Next.
In the Display Label, type a name for the application Tesorio. This is the name that will be shown to users in the User Portal.
Optionally, you can enter a Description, adjust the User Portal Image and choose to hide or Show this application in User Portal. Under Advanced Settings, you can specify a value for the SSO IdP URL. If no value is entered, it will default to https://sso.jumpcloud.com/saml2/<applicationname>.
Click Save Application and then Configure Application.
Step 2
Now its time to configuration the application to work with Tesorio.
You will want to enter https://dashboard.tesorio.com/saml/acs/
Idp Entity ID
SP Entity ID
ACS URLs
Next Set
SAMLSubject NameID: email
SAMLSubject NameID Format: urn.oasis:names:tc:SAML:2.0:nameid-format:persistent
Signature Algorithm: RSA-SHA256
Sign: Assertion
Default RelayState: https://dashboard.tesorio.com/dashboard/
Login URL: https://dashboard.tesorio.com/saml/acs/
Make sure the following 2 checkboxes are checked.
Add the following attributes this is case sensitive
Email:email
FirstName:firstname
LastName:lastname
STEP 3
Copy the Metadata URL from the top
Save the Application configuration at the bottom left of screen
Proceed to the SAML Tesorio setup page and enter the metadata url you copied
Save new metadata URL.
After you have added the application to the group of users in JumpCloud there are two ways to test.
Use the JumpCloud Portal button
Head directly to the Tesorio SSO login page.