Linking JumpCloud as a source

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Contents

Alpha release

This source is currently in alpha. The interface and available tables may change.

JumpCloud is a cloud directory platform for identity, access, and device management. Linking it as a source syncs your users, devices, groups, SSO applications, device policies and their results, alerts, identity risk events, System Insights device data, and Directory Insights activity events into the PostHog data warehouse, so you can join identity and security data with your product data.

Prerequisites

To connect JumpCloud, you need:

  • A JumpCloud administrator account with API access.
  • Your admin API key, found in the JumpCloud Admin Portal under your account menu (click your initials in the top-right corner, then My API Key).
  • A Directory Insights subscription if you want to sync the events table. How far back events are available depends on your Directory Insights retention (up to 90 days).
  • System Insights enabled for your devices if you want to sync the system_insights_* tables.

Adding a data source

  1. In PostHog, go to the Sources tab of the data pipeline section.
  2. Click + New source and click Link next to this source.
  3. Enter your credentials (see Configuration below) and click Next.
  4. Select the tables you want to sync, choose a sync method and frequency, then click Import.

Once the syncs are complete, you can start querying this data in PostHog.

Enter your JumpCloud admin API key to sync your directory and activity data.

Find your API key in the JumpCloud Admin Portal: click your account initials in the top-right corner and select My API Key.

The events table requires a Directory Insights subscription. If you're an MSP/MTP admin managing multiple organizations, also enter the organization ID the key should act on.

You'll be asked for:

  • API key
  • Region: choose between US (console.jumpcloud.com) and EU (console.eu.jumpcloud.com).

Sync modes

Each table can be synced in one of several modes, depending on what the source supports:

  • Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
  • Incremental – only new or updated rows are synced on each run, using a cursor field (such as an updated_at timestamp). Cheaper than a full refresh, but deletes aren't captured.
  • Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
  • Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.

See sync methods for a full explanation of how each mode works and how to choose between them.

The events table (Directory Insights) supports incremental sync: each run only fetches events newer than the last synced event timestamp. All other tables sync as a full refresh — each sync replaces the contents of the table.

The association tables (user_group_members, system_group_members, application_users, application_user_groups, and system_users) request JumpCloud once per parent group, application, or system, so a large directory takes longer to sync.

The policies, policy_results, policy_statuses, alerts, alert_occurrences, identity_risk_events, and system_insights_* tables also sync as a full refresh. policy_statuses holds the latest result of each policy on each device, and alert_occurrences holds each time an alert fired. Both request JumpCloud once per policy or alert. The system_insights_* tables hold device inventory and security posture (installed apps and programs, patches, disk encryption, browser extensions, OS versions, and more). Join them to systems on system_id.

Configuration

OptionTypeRequired
API keypasswordYes
RegionselectYes
Organization ID (optional, MSP/MTP only)textNo

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
users

User identities in the JumpCloud directory, including their account state and profile attributes.

Full refresh—_id
systems

Devices (workstations and servers) managed by the JumpCloud agent.

Full refresh—_id
user_groups

User groups used to grant collections of users access to resources (apps, systems, networks).

Full refresh—id
system_groups

Device groups used to apply policies and access to collections of systems.

Full refresh—id
applications

SSO applications configured in JumpCloud (SAML, OIDC, and bookmark apps).

Full refresh—_id
user_group_members

Users that are members of each user group, one row per group and user.

Full refresh—group_id, id
system_group_members

Systems that are members of each system group, one row per group and system.

Full refresh—group_id, id
application_users

Users bound to each SSO application, directly or through a user group.

Full refresh—application_id, id
application_user_groups

User groups bound to each SSO application.

Full refresh—application_id, id
system_users

Users bound to each system, directly or through a user or system group, so they can log in to it.

Full refresh—system_id, id
policies

Device policies configured in JumpCloud, each built from a policy template.

Full refresh—id
policy_results

Every recorded application of a policy to a device, with its outcome. Use it to follow compliance over time.

Full refresh—id
policy_statuses

The latest result of each policy on each device it applies to: the current compliance state.

Full refresh—policy_id, id
alerts

Alerts raised by JumpCloud for device and identity health, with their status and severity.

Full refresh—objectId
alert_occurrences

Each time an alert fired, with the context of that occurrence.

Full refresh—alert_id, occurredAt
identity_risk_events

Risk-scored identity events detected by JumpCloud, such as risky logins, with their risk factors and resolution.

Full refresh—objectId
events

Directory Insights activity events (console, SSO, RADIUS, LDAP, systems, and directory changes). Only syncs the last 90 days on initial sync, bounded by your Directory Insights retention

Incremental, Full refreshtimestampid
system_insights_alf

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_apps

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_battery

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_bitlocker_info

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_browser_plugins

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_chrome_extensions

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_disk_encryption

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_disk_info

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_firefox_addons

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_kernel_info

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_linux_packages

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_logged_in_users

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_os_version

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_patches

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_programs

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_safari_extensions

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_secureboot

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_sip_config

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_system_info

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_uptime

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_usb_devices

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_users

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_windows_security_center

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——
system_insights_windows_security_products

Device data reported by System Insights, one row per item per device. Requires System Insights to be enabled

Full refresh——

Troubleshooting

  • If the connection fails with an authorization error, the API key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
  • If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.

If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.

Still have questions?

Was this page useful?