Skip to content
All guidesGetting started

Connect JumpCloud (identity audit)

A dedicated Read Only integration administrator and its API key — per-user MFA status, enforcement gaps, console admins, and elevated users.

  1. 1Configure the JumpCloud API key for the read-only audit connector. Before you begin — this connector reads your JumpCloud directory to audit: • MFA enrollment and coverage • Users with elevated or sudo access • Password hygiene • Inactive or stale accounts Do not use a personal administrator account unless necessary. A dedicated integration administrator prevents the connector from failing when an employee leaves, changes roles, or has their account suspended or deleted. Deleting an administrator immediately invalidates its API and connect keys.
  2. 2Step 1 — Create a dedicated integration administrator. This step requires an account with the Administrator with Billing role. 1. Sign in to the JumpCloud Admin Portal. 2. In the left navigation, select Settings. 3. Open the Administrators tab. 4. Select + Admin. 5. Select As New. 6. Enter an identifiable name, such as: First name: Cybermatic Last name: Scanner 7. Enter a unique, monitored email address for the integration account. 8. Under Permissions, select Read Only. 9. Select Enable API access. 10. Select Create. 11. Open the invitation email sent by JumpCloud. 12. Set a strong, unique password for the integration administrator. 13. Complete the required administrator MFA enrollment. New JumpCloud administrators have API access disabled by default. Only an Administrator with Billing can enable it.
  3. 3Step 2 — Sign in as the dedicated administrator. 1. Sign out of your personal JumpCloud administrator session. 2. Sign in using the new Cybermatic Scanner integration administrator account. 3. Complete MFA when prompted. 4. Confirm that the account can view the necessary user, group, system, MFA, and password information. 5. Confirm that it cannot create, update, or delete directory objects.
  4. 4Step 3 — Open the API-key page. 1. While signed in as the dedicated administrator, open the administrator account menu. 2. Depending on your JumpCloud portal layout, select either: • Your account name in the bottom-left, or • Your initials/avatar in the account menu. 3. Select My API Key. JumpCloud's current documentation primarily shows the account name in the bottom-left for accessing My API Key, although some portal views continue to display the account initials menu. If you receive a permission error — you may see: "You don't have permission to view or generate an API Key." Have an Administrator with Billing perform the following: 1. Go to Settings → Administrators. 2. Open the dedicated integration administrator. 3. Select Enable API access. 4. Select Save. 5. Sign out and sign back in as the integration administrator. Only an Administrator with Billing can enable API access for another administrator.
  5. 5Step 4 — Generate the API key. 1. On the My API Key page, set Expiration to No Expiration. (If you set a timeline like 90 days, make sure you renew the key before it expires.) 2. Select Generate New API Key. 3. Copy the entire key immediately. 4. Confirm that the value begins with jca_. 5. Store it directly in an approved password manager or secrets-management platform. JumpCloud displays the API key only when it is created, so it must be securely captured at that time.
  6. 6Step 5 — Connect JumpCloud to Cybermatic. 1. Sign in to Cybermatic. 2. Open: Connections 3. Under the Identity providers section, select: JumpCloud 4. Locate the field labeled API key. 5. Paste the complete jca_... value. 6. Do not add quotation marks, spaces, or line breaks. 7. Confirm that the connector is pointed to the correct JumpCloud organization. 8. Select Connect. Cybermatic saves the connection and starts the initial scan. Timing note: the first scan captures the directory as it exists at that moment. Users you add afterwards appear at the next scheduled scan — or immediately if you press Scan now.
  7. 7What Cybermatic checks. • Every active managed user appears on the Identities page with their MFA status — enrolled users show low risk, unprotected ones high, and unprotected elevated users critical. • MFA enrollment vs enforcement: JumpCloud treats these separately, and Cybermatic flags users for whom MFA isn't required at sign-in — enrollment without enforcement protects nothing. • Console administrators: admins linked to directory users are checked for MFA (Critical if missing); standalone console admins are surfaced for manual review. • Sudo-elevated users without MFA (Critical — their password is root on every bound device). • Password hygiene signals such as widespread never-expiring passwords. Sign-in recency isn't available through JumpCloud's standard API (it lives in their separate Directory Insights product), so stale-account detection isn't included for this connector.
  8. 8Troubleshooting. "JumpCloud auth failed: the API key was rejected (401)" — the key was regenerated (which revokes the old one), expired, or its administrator was deactivated; create a fresh key and use Connections → Update credentials. A user you just added isn't showing — the scan ran before they existed; press Scan now on the Identities or Connections page. Findings look thin — the key inherits its administrator's permissions; confirm the integration administrator's Read Only role and API access are intact. Rotating the key — generate the new key, update it in Cybermatic, and confirm the next scan succeeds. Remember regeneration revokes the old key instantly.

Tip: JumpCloud's sharpest gap is enrolled-but-not-enforced MFA: a user can own a TOTP and still be signable-in on password alone. When that finding appears, enforcement — not enrollment — is the fix.

More in Getting started