Skip to main content

Documentation Index

Fetch the complete documentation index at: https://jam.dev/docs/llms.txt

Use this file to discover all available pages before exploring further.

SSO and Directory Sync are available on the Enterprise plan only. Contact sales to upgrade.
Single Sign-On settings showing GoogleSAML for @acme.com and Google Workspace with 21 synced members

How it works

SSO (Single Sign-On) connects your identity provider to Jam for authentication. Team members log in using their existing corporate credentials instead of a separate Jam password. Directory Sync automatically reflects user changes from your IdP in Jam. Changes to your IdP sync automatically to your Jam workspace with no manual work.

Supported identity providers

  • Okta
  • Azure AD
  • Google Workspace
  • Any SAML-compatible provider

Configure

Configure Single Sign-On
1

Open Settings

Go to Settings.
2

Start the SSO setup

In the Access section, click Setup next to Identity Provider.
3

Follow the guided walkthrough

Follow the setup walkthrough for your identity provider.
4

Finish configuration in your IdP

Complete the required configuration steps on your identity provider’s side.
You should now see your IdP listed in the Access section. Members can now log in with SSO.
SSO is configured for a single domain by default. Need multiple domains? Contact our team to enable additional domains.

User management

How you manage team members depends on whether Directory Sync is enabled.
Members list with the Active Directory sync enabled banner and 21 synced membersAutomated Management
  • User provisioning: Happens in your identity provider
  • New user notifications: Users get email notifications when provisioned
  • Role management: Handle manually in Settings → Members
  • User removal: Remove from IdP to revoke Jam access automatically
  • Group sync: Manage access via user groups in your IdP
Access directory sync management in Settings → Members.
User groups cannot be mapped to specific Jam roles automatically. Role assignment requires manual configuration.

FAQ

Yes. SSO handles authentication while Directory Sync manages user provisioning. You can enable either feature independently.
Jam supports all major identity providers, including Okta, Azure AD, Google Workspace, and any SAML-compatible provider.
Not automatically. While you can sync user groups from your IdP, role assignment requires manual configuration in Settings → Members.
With Directory Sync enabled, the user automatically loses access to Jam when they are removed from your IdP.