Six SSO paths
SAML 2.0, OIDC, ClassLink, Clever, OneRoster 1.1, SCIM 2.0, plus LTI 1.3 carrying auth in the fall 2026 LMS integration.
For institutions · SSO
SAML 2.0, OIDC, ClassLink, and Clever. Students and teachers authenticate through your identity provider, they never see our login screen.
This is the technical page your IT team wants. It covers the supported protocols, what we need from your identity provider, and what deployment looks like from start to finish. Non-technical readers may prefer the institutions hub.
For SAML:
NameID (persistent, institution-scoped), email, givenName, sn, and one of role or eduPersonAffiliation (to distinguish student/teacher/admin).eduPersonPrincipalName, ou (for department-level segmentation), dateOfBirth or grade (to drive COPPA under-13 mode in K-12).For OIDC: client ID / client secret provisioned on your side, redirect URI we provide, and the same attribute mapping via scopes/claims.
Roster sync is optional. With sync enabled, teachers see their assigned class rosters inside bulk mode, and per-class detection thresholds can be set. We support:
For institutions already on ClassLink or Clever with a vanilla attribute set, the timeline compresses to 7–10 business days.
SAML 2.0, OIDC, ClassLink, Clever, OneRoster 1.1, SCIM 2.0, plus LTI 1.3 carrying auth in the fall 2026 LMS integration.
Teachers can use the tool without roster integration. Sync enables per-class thresholds and roster-aware bulk mode when institutions want it.
Institutions already on ClassLink or Clever with a vanilla attribute set deploy in 7–10 business days; full SAML kickoff is 3–6 weeks.