SSO User Attributes and Account Creation
When a patron signs in to ePlatform using Single Sign-On (SSO), their ePlatform account is created or updated using the attributes sent by your identity provider.
Correct attribute mapping ensures that ePlatform receives the patron information your library needs, including their identifier, name, role, class, or year level.
How SSO accounts are created
The first time a patron signs in using SSO, ePlatform uses the information sent by the identity provider to create their patron account.
The information is sent through SAML attributes or claims configured by your identity provider. Examples of identity providers include Microsoft Entra ID, Google Workspace, ADFS, and other SAML services.
After the account has been created, the patron can use the same SSO method for future sign-ins.
How SSO accounts are updated
When an existing patron signs in using SSO, ePlatform can update their account using the information supplied during that sign-in.
For example, if a mapped form, class, or year-level value changes in the source system, the updated value can be sent to ePlatform the next time the patron signs in.
Only information included in the configured SSO attributes can be received and used by ePlatform.
SSO user attributes
Attributes are individual pieces of patron information sent by your identity provider during SSO.
| Patron information | How it is used |
|---|---|
| Username or barcode | Provides an identifier for the patron account. |
| Name | Identifies the patron in the ePlatform Admin area. |
| Email address | Adds the email address supplied by the identity provider. |
| Role | Provides the patron role supplied by the source system. |
| Form or class | Can assign the patron to the corresponding class or category. |
| Year level | Records the patron’s year level and supports year-level content restrictions. |
| Date of birth | Supports age information and age-based content restrictions when configured. |
Basic and additional attributes
Basic account information
An SSO assertion may send only basic information, such as:
- name;
- email address; and
- username or barcode.
This information may be sufficient to create the patron account and allow the patron to sign in.
Additional patron information
Additional attributes are required if you want ePlatform to receive information such as:
- role;
- form or class;
- year level; or
- date of birth.
If these attributes are not included in the SSO assertion, the corresponding patron information will remain blank in ePlatform.
Configure attribute mapping
Your identity provider administrator must configure the attributes or claims included in the SSO assertion.
- Identify the patron information your library needs in ePlatform.
- Confirm that this information exists in your identity provider.
- Configure the corresponding SAML attributes or claims.
- Record the attribute names used by your identity provider.
- Contact ePlatform Support so the supplied attributes can be captured and aligned with the corresponding ePlatform fields.
Attribute names and configuration steps differ between identity providers. Follow the instructions provided by your identity provider and ePlatform Support.
Check the information received
After configuring or changing an attribute, test the connection using a patron account that contains the relevant information.
- Open your library’s ePlatform sign-in page.
- Sign in using the test account and the configured SSO method.
- Sign in to ePlatform separately using an administrator account.
- Open the Admin area.
- Select Patrons.
- Locate the test patron.
- Confirm that the expected information appears in the patron record.
Repeat the test with accounts containing different roles, forms, classes, or year levels when those attributes are being mapped.
If patron information is missing
If the patron can sign in but information is missing from their ePlatform account:
- Confirm that the information exists on the test account in the identity provider.
- Confirm that the corresponding attribute is included in the SSO assertion.
- Confirm that the attribute contains a value for the test account.
- Record the attribute or claim name being sent.
- Contact ePlatform Support with the results.
If basic attributes are received but form, class, or year-level information is blank, the additional attribute may not be mapped or may not yet be aligned with the corresponding ePlatform field.
Need help?
If accounts are not being created, updated, or populated correctly, submit a support request or email support@eplatform.co.
Include:
- your library name;
- the identity provider being used;
- the attribute or claim names being sent;
- the patron information that is missing; and
- whether the issue affects one account or multiple accounts.