# JumpCloud + Lutril: setup guide

> Lutril connects to JumpCloud with an administrator API key and governs the people in your JumpCloud organization: it reads every user with whether they hold sudo on their devices, whether multi factor is enrolled, and which user groups they belong to. It time boxes access two ways. Somebody with no account gets one created without a password, so JumpCloud sends its own activation mail and Lutril never holds a credential; the deadline suspends that account. Somebody who already has an account is added to one user group for the life of the grant, and the deadline removes that membership and nothing else. Lutril governs JumpCloud as an application here, not as the identity provider your access reviews are reconciled against.

Source: https://www.lutril.com/integrations/jumpcloud
Category: Security
Auth: api_key
Last verified: 2026-10-08

---

## Setup

1. [object Object]
2. Note the region your organization lives in. It is in the address you sign in to: console.jumpcloud.com for the United States, console.eu.jumpcloud.com for the European Union, console.in.jumpcloud.com for India. A key created in one region is not accepted by another.
3. In Lutril, connect JumpCloud, paste the API key and pick the matching region. Leave the Organization ID empty unless you are on a Managed Service Provider portal where one key reaches several organizations.
4. [object Object]
5. [object Object]
6. A grant only ever adds. Anyone already in the group they asked for is left exactly as they were, so a deadline can never take away a membership that Lutril did not grant.
7. Lutril does not detect JumpCloud console administrators. The only endpoint that lists them is scoped to Managed Service Provider portals and returns identifiers without addresses, so there is no reliable way to tie one to a person. What Lutril does report is sudo, which is local administration on every device a person is bound to, and that is the standing privilege worth reviewing.

## Access requested

- An API key created by an administrator who can manage users and groups. The key inherits that administrator's rights.
- If your organization uses scoped API keys: users, users.create (to provision) and groups.

## References

- [JumpCloud documentation](https://jumpcloud.com/support/jumpcloud-apis)
- [JumpCloud console](https://console.jumpcloud.com)
- [JumpCloud APIs overview](https://jumpcloud.com/support/jumpcloud-apis)
- [API v1 reference](https://docs.jumpcloud.com/api/1.0/index.html)
- [API v2 reference](https://docs.jumpcloud.com/api/2.0/index.html)
- [Suspend and reactivate users](https://jumpcloud.com/support/suspend-and-reactivate-users)
- [Get started with user groups](https://jumpcloud.com/support/get-started-user-groups)
