What QX offers
- A person signs in to QX with the SSO login in JumpCloud, through the OIDC protocol. QX never sees the password.
- JumpCloud creates, updates and deactivates the users of QX through user provisioning, with the SCIM 2.0 protocol. QX receives users only. The groups stay in JumpCloud.
- JumpCloud has an owner group and an operator group. At each login, QX gives the person the role of the group.
- The owner turns on required SSO for the whole organization. With the rule on, nobody in the organization signs in with a password, including the owner.
- When the organization requires two-step verification, QX accepts only an SSO login in which the person used a second factor in JumpCloud.
- A session that starts with the SSO login expires 8 hours after the login. It does not extend.
The order of the work
Do the steps in this order:- The IT team creates the OIDC app in JumpCloud.
- The IT team binds the two groups to the app.
- The owner configures the SSO connection in QX.
- The IT team pastes the QX login URL into the app.
- The owner issues the provisioning key.
- The IT team activates user provisioning in JumpCloud.
- The owner does the login test.
- The owner enables SSO login.
- The owner turns on required SSO.
- The JumpCloud user of the owner has the same e-mail as the QX user of the owner.
- The owner is in the owner group.
The QX addresses
The owner sees the addresses in Settings › SSO, in the box Addresses for JumpCloud. Each address has a Copy button.
The login URL shows only after the owner saves the SSO connection. The other two addresses are these:
1. Create the OIDC app in JumpCloud
- In the JumpCloud Admin Portal, go to Access › SSO Applications.
- Click + Add New Application.
- Select Custom Application and click Next.
- Select Manage Single Sign-On, then Configure SSO with OIDC, and click Next.
- In Display Label, type
QX. - Turn on Show this application in User Portal. The portal tile opens QX.
- Click Next, then Configure Application.
- In the SSO tab, in Redirect URIs, paste the QX redirect URI.
- In Client Authentication Type, select Client Secret Basic. QX does not work with the other two types.
- Leave Login URL empty for now. Step 4 fills the field. JumpCloud accepts the app with no Login URL (not confirmed in an official source).
- In Subject Claim, keep JumpCloud User ID (Recommended Default).
- In Attribute Mapping, select the scopes Email and Profile. Without the e-mail, QX refuses each login.
- Select include group attribute and type
groupsas the name of the groups attribute. - Click Activate. JumpCloud shows the client secret only once. Copy the client ID and the client secret, and click Got It.
2. Bind the two groups to the app
- Open the User Groups tab of the app.
- Select the owner group and the operator group.
- Click Save.
3. Configure the SSO connection in QX
The owner does these steps in QX:- Open Settings › SSO and click Configure SSO connection.
- In Region, select the region of the JumpCloud account: US, EU or India.
- In Client ID and Client secret, paste the values of step 1.
- In Owner group and Operator group, type the name of each group exactly as JumpCloud shows it.
- Click Save SSO connection.
4. Paste the login URL into JumpCloud
- Open the app in JumpCloud, in the SSO tab.
- In Login URL, paste the QX login URL.
- Save the app.
5. Issue the provisioning key
The owner does these steps in QX:- In Settings › SSO, click Manage provisioning keys.
- Click Issue provisioning key, then Issue key. If the login of the owner is older than 15 minutes, QX asks for the password.
- Copy the key. QX shows the key only once. The key starts with
qxp_. - Give the key to the IT team through a safe channel. Do not send the key by e-mail or by message.
- After the IT team pastes the key, check I pasted the key into JumpCloud and click Back to the keys.
6. Activate user provisioning in JumpCloud
- Open the Provisioning tab of the app.
- Leave Use mTLS off.
- In Base URL, paste the user provisioning base URL, with no slash at the end.
- In Token, paste the provisioning key.
- In Test User Email, type an e-mail that no QX user has. JumpCloud creates this test user and then deletes it.
- Click Test Connection.
- Turn off Enable management of User Groups and Group Membership in this application. QX does not receive groups.
- Click Activate. Do not click Save.
externalId:
- In the Provisioning tab, open User Attributes and click Edit.
- Click +Add Attribute and select the type Expression.
- In the JumpCloud attribute field, type this expression:
- In the SCIM attribute field, select
externalId. - Click Update, then Activate again.
externalId carries the JumpCloud User ID. QX recognizes the person by this identifier. The e-mail alone never identifies the person.
7. Do the login test
- In Settings › SSO, the owner clicks Test login.
- QX opens JumpCloud. The owner signs in with their own user.
- QX shows “The login test passed. The SSO connection is verified.”
- User provisioning already linked the user of the owner.
- The owner is in the owner group.
- When the organization requires two-step verification, the owner signs in to JumpCloud with the second factor.
8. Enable SSO login
- In Settings › SSO, the owner clicks Enable SSO login.
- A person of the operator group opens QX from the tile of the JumpCloud portal and checks the login.
9. Turn on required SSO
- In Settings › SSO, the owner clicks Turn on required SSO.
- The owner reads the warning and clicks Turn on required SSO again.
How QX treats each person
- User provisioning creates the user of a new person. The Users screen shows “Waiting for SSO login”. The first SSO login activates the user and gives the role of the group.
- When the person already has a QX user, user provisioning links that user by the e-mail, in the same organization. The user keeps the history.
- After a group change, the role changes at the next SSO login. To change the group, add the person to the new group before you remove the person from the old group.
- To deactivate a person, remove the person from both groups or suspend the person in JumpCloud. User provisioning deactivates the user in QX. All sessions of the user end at the same moment.
- To reactivate a person, put the person back in a group. The user goes back to “Waiting for SSO login” and signs in again at the next SSO login.
- The name and the e-mail of the person change only in JumpCloud. The owner sees the user in QX, but does not change them.
Replace the provisioning key
The SSO connection keeps up to 2 active keys. With two keys, JumpCloud switches to the new key with no gap in user provisioning.- The owner issues a new key, as in step 5. In a session that started with SSO, when the login is older than 15 minutes, QX asks for the identity confirmation in JumpCloud.
- The IT team opens the Provisioning tab of the app and expands Configuration Settings.
- The IT team pastes the new key into Token Key and clicks Update. The Save button does not change the key.
- The owner checks the Last use column of the new key.
- The owner clicks Revoke on the old key, then Revoke key.
Replace the client secret
- In JumpCloud, the IT team opens the app and selects Actions › Regenerate Secret, then Regenerate.
- The owner opens Edit SSO connection, pastes the new secret into Client secret and clicks Save SSO connection.
When JumpCloud is down
With required SSO on, nobody signs in to QX while JumpCloud is down. The open sessions continue until they expire.- If an owner still has an open session, the owner clicks Turn off required SSO in Settings › SSO.
- If no owner has an open session, ask QX support. Support turns off required SSO and writes the reason in the audit log.
- A person with no password clicks Forgot your password? on the login page and sets a password.
- When JumpCloud is back, the owner clicks Turn on required SSO.