SSO - Jam Documenation
How it works
SSO (Single Sign-On) connects your identity provider to Jam for authentication. Team members log in using their existing corporate credentials instead of a separate Jam password. Directory Sync automatically reflects user changes from your IdP in Jam. Changes to your IdP sync automatically to your Jam workspace with no manual work.
Supported identity providers
- Okta
- Azure AD
- Google Workspace
- Any SAML-compatible provider
Configure
- SSO setup
- Open Settings Go to Settings.
- Start the SSO setup In the Access section, click Setup next to Identity Provider.
- Follow the guided walkthrough Follow the setup walkthrough for your identity provider.
- Finish configuration in your IdP Complete the required configuration steps on your identity provider’s side.
You should now see your IdP listed in the Access section. Members can now log in with SSO.
SSO is configured for a single domain by default. Need multiple domains? Contact our team to enable additional domains.
- Directory Sync setup
- Open Settings Go to Settings.
- Start the Directory Sync setup In the Access section, click Setup next to Active Directory.
- Follow the guided walkthrough Complete the step-by-step configuration walkthrough for your IdP.
- Select user groups to sync (optional) Choose which user groups from your IdP should sync to Jam. This step is optional.
You should now see your IdP listed in the Access section. New users added to your IdP automatically join your workspace.
Provisioned users get the Creator role by default. You’ll need to adjust roles manually in Settings → Members.
User management
How you manage team members depends on whether Directory Sync is enabled.
With Directory Sync
User provisioning: Happens in your identity provider.
- New user notifications: Users get email notifications when provisioned.
- Role management: Handle manually in Settings → Members.
- User removal: Remove from IdP to revoke Jam access automatically.
- Group sync: Manage access via user groups in your IdP.
Access Directory Sync management in Settings → Members.
User groups cannot be mapped to specific Jam roles automatically. Role assignment requires manual configuration.
Manual Management
User provisioning: Add users directly in Settings → Members.
- Role management: Assign and modify roles in Jam.
- User removal: Remove users manually in Settings → Members.
All user management happens in Settings → Members.
User groups cannot be mapped to specific Jam roles automatically. Role assignment requires manual configuration.
FAQ
Can I use SSO without Directory Sync?
Yes. SSO handles authentication while Directory Sync manages user provisioning. You can enable either feature independently.
What identity providers are supported?
Jam supports all major identity providers, including Okta, Azure AD, Google Workspace, and any SAML-compatible provider.
Can I map user groups to specific Jam roles?
Not automatically. While you can sync user groups from your IdP, role assignment requires manual configuration in Settings → Members.
What happens when I remove a user from my identity provider?
With Directory Sync enabled, the user automatically loses access to Jam when they are removed from your IdP.