Skip to content
Security and identity

JumpCloud and OneLogin integration

Plan how JumpCloud and OneLogin should share data across your business. Work with Stacksync engineers on record mapping, system access, and the requirements for running the integration.

  • Scope your workflow with an integration engineer
  • Review the systems, records, and updates you need

Teams building with Stacksync

Plan the connection your business needs

Explore a JumpCloud and OneLogin integration with a Stacksync engineer. Stacksync support for JumpCloud and OneLogin is not established by the connector documentation reviewed for this page. Start with one record and the update your business needs to identify an implementation path.

01 / Business process

Start with one meaningful update

Identify the record that changes in JumpCloud or OneLogin, where it needs to appear, and which team depends on it.

02 / Data access

Establish the available connection

Bring the objects, account editions, and required directions. An engineer can review the connector path, permissions, and field access.

03 / Success criteria

Define a result you can verify

Agree on record matching, acceptable delay, expected volume, and how your team will resolve failed updates.

Technical referenceAvailable documentation, candidate record relationships, and questions for your technical review.

What records can you sync?

Explore the record types and read/write requirements for each system.

JumpCloudConnection and object support require review

Record types to review with Stacksync

Record typeCoverage and requirements
System Users (Users)Confirm support for this record type and the direction you need.
User GroupsConfirm support for this record type and the direction you need.
Systems (devices)Confirm support for this record type and the direction you need.
System GroupsConfirm support for this record type and the direction you need.
Applications (SSO)Confirm support for this record type and the direction you need.
PoliciesConfirm support for this record type and the direction you need.

Discuss JumpCloud requirements

OneLoginConnection and object support require review

Record types to review with Stacksync

Record typeCoverage and requirements
UsersConfirm support for this record type and the direction you need.
RolesConfirm support for this record type and the direction you need.
Apps (app instances)Confirm support for this record type and the direction you need.
GroupsConfirm support for this record type and the direction you need.
Mappings (mapping rules)Confirm support for this record type and the direction you need.
EventsConfirm support for this record type and the direction you need.

Discuss OneLogin requirements

Connection requirements and limits

JumpCloud

Integration interface
JumpCloud REST API - v1 (console.jumpcloud.com/api) for Systems, System Users, and Commands; v2 (/api/v2) for User Groups, System Groups, Applications, Policies, and resource associations; plus the Directory Insights API (api.jumpcloud.com/insights/directory/v1/events) and Webhook Channels for outbound events.
Authentication
Confirm the credentials, API plan, and permissions required for JumpCloud.
Change detection
Confirm how Stacksync detects changes for this connector and the objects you need.
Read access
Confirm with Stacksync
Write access
Confirm with Stacksync

Limitations to check

  • Confirm Stacksync support for JumpCloud and the record types your workflow needs.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.

OneLogin

Integration interface
OneLogin API (REST, v1 and v2 resource endpoints on <subdomain>.onelogin.com) plus the Event Webhook (Event Broadcaster) for event delivery
Authentication
Confirm the credentials, API plan, and permissions required for OneLogin.
Change detection
Confirm how Stacksync detects changes for this connector and the objects you need.
Read access
Confirm with Stacksync
Write access
Confirm with Stacksync

Limitations to check

  • Confirm Stacksync support for OneLogin and the record types your workflow needs.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.

Prepare your technical review

Use the worksheets and reference checks to capture record identity, ownership, and the result your business expects.

Implementation reference

Record identity and field ownership

Use these data-model references to describe the records your connection needs. They are planning examples; connector availability and supported operations must be established before implementation.

Download the mapping worksheet

CSV · No email required · Record matching, ownership, and test cases

Record matchingSystem Users (Users) Users

Compare whether JumpCloud System Users (Users) and OneLogin Users describe the same application user or identity in your business.

JumpCloud
Object support to establish
OneLogin
Object support to establish

Record identity

Use the immutable user ID within the tenant or directory. Do not equate an application user with a CRM customer contact.

Field ownership

Identity and application owners approve account lifecycle and access changes; synchronize only approved attributes.

Fields to include

  • Source user ID
  • Tenant reference
  • Account status
  • Group references
Record matchingUser Groups Groups

Compare whether JumpCloud User Groups and OneLogin Groups describe the same group or membership in your business.

JumpCloud
Object support to establish
OneLogin
Object support to establish

Record identity

Keep group IDs and membership relationships separately from group names.

Field ownership

The access owner controls membership; reporting a group is different from granting its permissions.

Fields to include

  • Source group ID
  • Member references
  • Tenant reference
  • Group type

Architecture decision

Choose how to connect your systems

Choose a method around one example record and the update your business needs. Use System Users (Users) / Users to review record matching and confirm Stacksync support for the required operations. Compare ongoing sync, a custom workflow, and a scheduled export against that requirement.

Stacksync managed sync

Best fit
Review compatibility with a Stacksync engineer using an example of the records and updates you need.
Operating responsibility
Fits ongoing record synchronization when the required operations are supported. Add workflow steps for approvals or business actions that go beyond copying fields.
Before you choose
Check record matching: Use the immutable user ID within the tenant or directory. Do not equate an application user with a CRM customer contact. Verify field coverage, deletion handling, and how changes are detected.

Native vendor integration

Best fit
A vendor-built integration may fit if it supports your JumpCloud and OneLogin record types.
Operating responsibility
Can reduce setup for a supported workflow. You may need another method for records or business steps it does not cover.
Before you choose
First check whether either vendor offers this integration. If available, verify System Users (Users) / Users, update direction, account tier, and related-record handling.

Custom API or workflow

Best fit
Consider when JumpCloud and OneLogin need a transformation, approval, or action outside a direct record sync.
Operating responsibility
Provides control over business steps; the team owns credentials, version changes, error queues, and reconciliation.
Before you choose
Verify endpoint permissions, pagination, quotas, duplicate detection, and failure recovery. Separate reading history from actions that send messages, grant access, or post transactions.

File or scheduled snapshot

Best fit
Consider for a one-time JumpCloud / OneLogin migration or a reporting need with an explicit freshness window.
Operating responsibility
Can simplify a bounded transfer; later changes and deletion history require another extraction or a separately designed incremental process.
Before you choose
Record the extraction cutoff, source IDs, encoding, date/number formats, and reconciliation totals.

Workflow reference

From a business event to the right update

Open a workflow to see its trigger, record relationships, and expected result.

Application user or identity sync test

Starting event: A change to the selected System Users (Users) or Users record needs a defined result in the other system.

  1. Start with JumpCloud System Users (Users) and OneLogin Users. Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve tenant and group references and establish a protected administrative-account policy.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Test a renamed login, disabled account, missing group, and a user existing in two tenants.

If it fails: Review access impact before retrying a lifecycle change; reconcile current identity state and retain an approval trail.

Group or membership sync test

Starting event: A change to the selected User Groups or Groups record needs a defined result in the other system.

  1. Start with JumpCloud User Groups and OneLogin Groups. Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve user and tenant identities before membership changes.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Test removed membership, nested groups, and equal group names in different tenants.

If it fails: Recompute the approved membership delta before retrying; do not replay an outdated access grant.

Manage approved account changes across JumpCloud and OneLogin

Starting event: An approved identity change in JumpCloud needs to be reflected in the OneLogin process.

  1. Identify the tenant and immutable user ID in JumpCloud; determine whether Users or Groups has a legitimate relationship to that user.
  2. Separate reporting identity context from actions that create users, grant access, or deactivate accounts. Document the approval and effective date before any action.
  3. Keep identity attributes separate from customer contacts and exclude attributes unnecessary for the process.

Expected result: A rename preserves identity; an unapproved access change is withheld; a future-dated change waits until its approved time.

If it fails: Review current permissions and approval before retrying. A stale event must not restore access that has since been removed.

Production readiness

Test the behavior your business depends on

Keep both record IDs with the expected and actual result. Reconcile the same filters and time window in each system.

System Users (Users) / Users

Test case

Test a renamed login, disabled account, missing group, and a user existing in two tenants.

Expected result

The expected application user or identity relationship is preserved with no duplicate action or unintended write.

User Groups / Groups

Test case

Test removed membership, nested groups, and equal group names in different tenants.

Expected result

The expected group or membership relationship is preserved with no duplicate action or unintended write.

Direction and permissions

Test case

Bring an example source record and the intended destination operation to the compatibility review. Confirm the supported route before granting write access.

Expected result

Only an approved, supported direction and permitted fields are written.

Freshness and reconciliation

Test case

Measure source and destination times for the selected records under normal load and a burst. Reconcile IDs and values using the same filters and cutoff.

Expected result

The process meets its agreed freshness target and reconciliation has no unexplained differences.

Failure recovery

Find the cause. Restore the data flow.

Start with the failed record and the destination error, then inspect the source value, field requirements, and access.

Rejected or repeated application user or identity change

Investigate

Inspect JumpCloud System Users (Users) and OneLogin Users, their IDs, and the destination error.

Next action

Review access impact before retrying a lifecycle change; reconcile current identity state and retain an approval trail.

Rejected or repeated group or membership change

Investigate

Inspect JumpCloud User Groups and OneLogin Groups, their IDs, and the destination error.

Next action

Recompute the approved membership delta before retrying; do not replay an outdated access grant.

A record type or update is unavailable

Investigate

Check the JumpCloud and OneLogin connector guides, account permissions, and any operations marked On Request.

Next action

Ask the integration team to confirm a supported way to handle that record. Verify whether it needs connector configuration or a separate workflow step.

Source and destination disagree after a retry

Investigate

Compare current source values, destination validation, identity mappings, and any side effects already completed.

Next action

Stacksync issue retry reads the current source state. Decide the intended state before retrying or reverting; reconcile downstream effects separately.

Read the Stacksync issues dashboard guide for retry and revert behavior.

How updates move between JumpCloud and OneLogin

See how each system detects changes and which updates the other system can receive. Each direction has its own permissions and record requirements.

JumpCloud OneLogin Direction requires confirmation

Detect changesConfirm how Stacksync detects changes for this connector and the objects you need.

Apply updatesConfirm that Stacksync can create or update the records you need in OneLogin.

OneLogin JumpCloud Direction requires confirmation

Detect changesConfirm how Stacksync detects changes for this connector and the objects you need.

Apply updatesConfirm that Stacksync can create or update the records you need in JumpCloud.

Update timing and record limits

  • Measure initial-load and ongoing-change latency separately. Source detection, selected objects, account limits, and destination validation determine the observed delay.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.

Prepare JumpCloud and OneLogin access

Set up both accounts before testing the mapping. Use test records where available, and identify the account administrator who can approve access and help resolve setup errors.

JumpCloud setup checklist

  • Identify the JumpCloud account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for JumpCloud, including read/write support, authentication, and initial-load limits.

OneLogin setup checklist

  • Identify the OneLogin account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for OneLogin, including read/write support, authentication, and initial-load limits.

Prepare to go live

Record the fields each system can update, the first-load cutoff, both record IDs, the expected update delay, and who handles errors. Complete the tests before production before expanding to more records.

Use the JumpCloud and OneLogin planning worksheet to capture these decisions. Record the access owner in the worksheet and enter credentials only in the connection setup.

Talk to an engineer · Review current pricing

Security and control for your integrations

Use SSO and SCIM to manage access, secure connection options to reach your systems, and record-level retry and revert controls to resolve sync errors.

Explore security controls
FAQ

JumpCloud and OneLogin integration FAQ

Find the right integration path

Walk through your JumpCloud and OneLogin records, field mappings, and requirements with an integration engineer.