SAML / OAuth SSO for JSM: Secure Portal Access for External Customers

Most JSM portal access issues are identity problems, not security ones. miniOrange SSO for JSM Customers authenticates portal-only users through Okta, Entra ID, AWS Cognito, or any IdP, controlling who gets in, which portal they land on, and their JSM organization, all from one add-on.

SSO for JSM customers with SAML 2.0, OAuth/OIDC, and 20+ identity providers

Why Teams Choose miniOrange

3X
Secure Logins
9+
2FA Methods
24x7
Developer Support

Solve Real Portal Access Problems With SSO for JSM Customers

Zero-Touch Customer Onboarding

Stop manually creating and mapping JSM portal customers. Automatically provision them into the right Organization at login, based on email domain or IDP group.

Multi-Organization Single Sign-On

Native JSM limits you to one IDP unless you're on Enterprise. Support multiple IDPs so clients from different companies can securely access the same portal with no conflict.

Comprehensive Protocol Support

Whether your IDP supports SAML or OAuth/OIDC, we support all the protocols. Go beyond SAML-only limitations and authenticate every customer, from any identity ecosystem.

Automated Portal Access Control

Secure sensitive service desks effortlessly. Map IDP groups and Jira organizations directly to specific JSM portals; unauthorized customers get blocked before they can even raise a ticket.

Right group, right portal access control for JSM customers

Everything You Need to Secure and Automate JSM Customer Access

SAML, OAuth, and OIDC SSO for portal-only customers

Authenticate external customers through any SAML 2.0, OAuth, or OpenID Connect identity provider. Works without an existing Guard subscription.

Automated organisation mapping

Customers are placed into the correct JSM organisation after successful login based on their IDP group membership or email domain. Customers land in the right JSM org automatically

Custom attribute mapping

Automatically map attributes from your IDP, name, department, role, or custom fields directly into JSM custom fields.

Multiple identity providers on a single portal

Support customers from different organisations, each authenticating through their own IDP, all on the same JSM portal.

Portal access control by IDP group

Gate access to specific JSM portals by a customer's IDP group or Jira orgs. Only users in the mapped group can reach the corresponding portal, while unauthorized access is blocked.

2FA for portal customers

The app can also support 2FA for portal-only customers via miniOrange’s in-house solution, supporting several authentication methods, including TOTP, WebAuthn, and OTP over email, etc.

Globally trusted by 3000+
premium clients and counting!

Google KPMG Mercedes-Benz Misumi Porsche

Here's what our awesome customers say

View All Reviews

We implemented the app for a client. The support was great, communication was quick, and we received immediate assistance with every issue. The app also works flawlessly, and the client is happy.

Thorsten Schmitt

⭐ ⭐ ⭐ ⭐ ⭐

We just implemented the solution in our customer. The portal-only customers had the same domain as their initial 50 agent and 50 guard users. The customers were more than 500 users. With this we did not need 500 guard licenses.

Kozma Zsolt

⭐ ⭐ ⭐ ⭐ ⭐

This app is awesome and just what we needed for the Okta to Atlassian integration to dump external users directly into their respective customer orgs, while still letting some customers authenticate using credentials....

Shaun Liles

⭐ ⭐ ⭐ ⭐ ⭐

We’ve been using SAML/OAuth SSO for JSM Customers for our Jira Service Management portal, and it has been a game-changer. The setup was straightforward, and the documentation is provider,...

Henning Ziech

⭐ ⭐ ⭐ ⭐ ⭐

Very good plug-in, which makes integration with IdP's much easier and also offers many other cool features. The configuration was relatively simple thanks to the instructions....

Michael Hachen

⭐ ⭐ ⭐ ⭐ ⭐

Frequently Asked Questions

Everything You Need to Know

Chat Icon Contact us

Configuration & Identity Providers

Which identity providers does the app support?
Any SAML 2.0 or OAuth / OpenID Connect compatible identity provider, including Okta, Azure AD, Google Workspace, AWS, OneLogin, Salesforce, Shibboleth, Oracle, Duo, and OpenAM.
Can we support multiple identity providers on the same portal?
Yes. The app supports multiple IDPs on a single JSM portal, so customers from different organisations can each authenticate through their own identity provider.
Can we map custom attributes from our IDP to JSM custom fields?
Yes. Any attribute passed through your IDP, name, department, roles, can be mapped directly to JSM custom fields.
Can we map customers to different JSM organisations automatically?
Yes. Customers are mapped to JSM organisations based on their IDP group membership or email domain automatically at login, with no manual mapping required.
Can we restrict which customers can access specific portals?
Yes. Portal access can be gated by the IDP group, so only customers who belong to the correct group in your identity provider can access the corresponding JSM portal.

Security & Support

Can we add 2FA on top of SSO for portal customers?
Yes. You can get miniOrange’s in-house 2FA solution that can be layered on top of SSO for an additional verification step.
What support is included?
24×7 support covering installation, configuration, IDP setup, and ongoing issues. Setup assistance is included with every license tier.
miniOrange Atlassian Contact Us

Book a Free Consultation with
Our Experts Today!

Schedule a call now!


Contact Us