To set up SSO using the SAML protocol, you need to connect to the SAML 2.0 Connect integration.
Before you begin
To successfully set up the SAML 2.0 integration, you’ll need a user with an admin role on Deel.
Step 1. Set up the SAML 2.0 Connector Integration
To set up the SAML 2.0 Connector Integration:
1. In the left sidebar, select Apps & Automation to expand its submenu, then select App Store.

The Apps overview page opens.
2. If the Welcome to your Deel Apps & Integrations prompt appears, select I’ll do that later to access the App Store.
3. In the Find apps search field, enter SAML 2.0.

4. Select SAML 2.0 Connect, described as SSO connector using SAML 2.0.

5. On the integration details page, select Connect SAML 2.0 Connect.

The SAML 2.0 Connect configuration form opens. It includes a Metadata URL field, an area to upload an XML metadata file, and an optional Entity ID field. The form saves your entered information automatically.

Keep this screen open, as you will need to get the Metadata URL from JumpCloud shortly.
Step 2. Set up a new JumpCloud application
To enable Deel to authenticate users via JumpCloud using the SAML 2.0 SSO protocol, follow these steps to create a new application in JumpCloud:
1. In the JumpCloud Administrator Portal, navigate to SSO Applications and select Add New Application.
2. Search for the SAML 2.0 application created by JumpCloud, Inc. and click Next.
3. Enter the display name for the application and ensure Show this application in User Portal is checked.
4. Click Save Application and then Configure Application.
5. Click on SSO and Copy Metadata URL to your clipboard.
6. Paste this URL in the Metadata URL field on Deel’s SAML 2.0 Connect configuration form. Alternatively, upload the XML metadata file supplied by your identity provider.
7. Still in Deel's SAML setup, optionally add an Entity ID (either text or URL to identify this integration in your Identity Provider) and click Connect & go to settings.
8. Enter this exact Entity ID in JumpCloud set up for both fields: IdP Entity ID & SP Entity ID.
9. Once the SAML Integration is connected in Deel, give it a name, and copy the Redirect URL.
This URL will be used in the JumpCloud configuration.
10. Go back to the JumpCloud > SSO Application configuration.
On the SSO tab, scroll down to the “ACS URLs” and paste the Redirect URL from Deel and click Save.
11. Specify the user groups that will have access to the SSO Application. Use the User Groups tab to assign roles.
Now, all users in the selected user group within the organization in Deel will be able to log in using the SSO Application.
12. Back in Deel's SAML 2.0 settings screen, click Enable to enable SSO for your organization.
Once enabled, SSO will be required for all employees to log in.
To disable SSO at any time, in the left sidebar, expand Apps & Automation and select App Store. If a welcome or onboarding dialog blocks the App Store, close it using the X in its upper-right corner.

In the Find apps search field, enter SAML 2.0.

For a connected SAML 2.0 Connect integration, select the three-dot menu next to the integration and choose Disconnect.

A disconnect confirmation modal appears. Stop at this modal unless you have been specifically instructed to confirm the disconnection.
