Setting Up Single Sign-On (SSO)
Single Sign-On (SSO) allows patrons to access ePlatform using credentials they already use with your school or organisation.
Setting up SSO requires coordination between your identity provider administrator, your IT team, and ePlatform Support.
Supported identity providers
ePlatform can support SSO connections using providers such as:
- Microsoft Entra ID or Azure AD;
- ADFS or another SAML provider;
- Google Workspace;
- MyLogin;
- OneLogin; and
- OpenAthens.
Configuration requirements differ between providers. Contact ePlatform Support before beginning the setup so your IT team receives the correct connection information.
How SSO works with ePlatform
When a patron signs in using SSO, their ePlatform account is created or updated using the information sent by your identity provider.
The information received through SSO can identify the patron and provide account details such as their:
- username or barcode;
- name;
- email address;
- role;
- form or class; and
- year level.
The information available in ePlatform depends on the attributes or claims configured in your identity provider.
Before you begin
Confirm that you have:
- the name of your identity provider;
- an IT or system administrator who can configure the provider;
- access to your provider’s SAML configuration;
- a list of the user information you want to send to ePlatform; and
- two or three accounts that can be used for testing.
If your library restricts titles by year level, confirm that your identity provider can send the appropriate year-level or form-class information.
Request SSO setup
- Submit a support request or email support@eplatform.co.
- Include your ePlatform library name.
- Provide the name of your identity provider.
- Include the contact details of the person coordinating the technical setup.
- Explain which user information you want the identity provider to send to ePlatform.
ePlatform Support will provide the connection information required for your identity provider.
Configure your identity provider
Your IT or system administrator will need to configure ePlatform within your identity provider.
For a SAML connection, this includes:
- importing the ePlatform metadata provided for the setup;
- configuring the SSO authentication URI or endpoint;
- confirming the Entity ID or Issuer details; and
- configuring the user attributes or claims sent to ePlatform.
Follow the instructions supplied by ePlatform Support and your identity provider. The exact names and locations of these settings depend on the provider being used.
Map user attributes
SAML attributes or claims determine which patron information is supplied to ePlatform when a user signs in.
| Information | Purpose in ePlatform |
|---|---|
| Username or barcode | Provides a unique identifier for the patron. |
| Name | Identifies the patron in the Admin area. |
| Email address | Adds the email information supplied by the provider. |
| Role | Identifies the patron’s supplied role. |
| Form or class | Can be used to assign the patron to the corresponding category. |
| Year level | Supports year-level information and related content restrictions. |
If the SSO assertion sends only basic information, ePlatform can create the patron account, but information such as form, class, or year level may remain blank.
After configuring the required attributes, contact ePlatform Support so the supplied information can be captured and aligned with the corresponding ePlatform fields.
Test the SSO connection
Test the connection with two or three accounts before providing SSO instructions to all patrons.
- Open your library’s ePlatform sign-in page.
- Use the configured SSO option.
- Sign in using the first test account’s existing credentials.
- Confirm that the patron reaches the correct ePlatform library.
- In the Admin area, open Patrons and confirm that the account has been created or updated.
- Confirm that the expected patron information has been received.
- Borrow an available eBook or Audiobook.
- Open the title and confirm that reading or playback begins.
- Repeat the test with the remaining accounts.
If your library uses year-level restrictions, test accounts with different year-level information.
If patron information is missing
If the patron can sign in but information such as form, class, or year level is missing:
- Confirm that the required attribute is included in the SAML assertion.
- Confirm that the test account contains a value for that attribute.
- Record the attribute or claim name used by your identity provider.
- Contact ePlatform Support with the results of the test.
Need help?
If the connection cannot be completed or a test account cannot sign in, submit a support request or email support@eplatform.co.
Include:
- your library name;
- the identity provider being configured;
- the SSO authentication URI or endpoint, if available;
- whether the problem affects one test account or all test accounts; and
- the error message displayed, if any.