SSO
Meadow supports SAML 2.0 so students and staff can sign in with your identity provider. The basic steps are to exchange metadata and configure two claims. Follow the steps below to complete the integration.
General Instructions
1. Download Meadow's SAML metadata
Your Integration Engineer will send you metadata via email. The metadata file has the information required to configure SSO with your identity provider:
- Entity ID
- Meadow public signing certificate
- Callback URLs
2. Configure your SSO provider
Instructions differ by provider. Create a SAML integration and application for Meadow in your SSO provider, for example Okta, Microsoft Entra (Azure AD), Google Workspace, or Shibboleth.
You can usually upload the SAML metadata file and the provider fills in the SSO parameters. If it does not accept the file, enter Meadow's Entity ID, public certificate, and callback URLs from the metadata by hand.
If your provider requires .pem format, reformat the certificate with openssl or another tool.
3. Confirm claims for email and student ID
Include these claims in the SAML response.
- Email: Add if your IdP does not send it by default.
Email- or
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- EmployeeId: Map this claim to the student ID in your system.
EmployeeId- or
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/EmployeeId
Claim names are case-sensitive.
4. Assign production users
Make sure students and staff who will use Meadow are assigned access to sign in to this application through SSO. We recommend allowing all users to sign in; we will not create accounts based on SSO attempts. Only users already in Meadow will be allowed to log in.
5. Send your federation metadata
Send your Meadow contact the Federation Metadata XML URL or file from your identity provider. For Microsoft Entra, follow Microsoft Entra.
6. Await confirmation from Meadow
Meadow loads your metadata into our system, then enables SSO. We will also create admin accounts for one or more school staff.
7. Test signing in
Sign in as an admin with your school account. This confirms that SSO works for admins.
Next, sign in with a real or test student account to confirm that SSO works for students. To show up in Meadow, the student must be registered in the prior, next, or current term.
If you are unable to sign in, send a test student's username and password to your Meadow contact to test from the Meadow side. Do not send credentials for a real student's account.
Microsoft Entra
- Go to portal.azure.com.
- Open Microsoft Entra ID.
- Open Enterprise applications.
- Select New application, then Create your own application. Name it "Meadow" or another name you prefer. Choose a non-gallery application.
- Select Set up single sign on, then SAML. If the mode is not SAML, choose Change single sign-on mode.
- Select Upload metadata file, upload the SAML metadata from Meadow and save. Close the Basic configuration panel.
- Open Attributes & Claims. The attribute that holds a student ID varies by directory.
emailaddressis usually configured already. Confirm email is included in the SAML response. Claim names are case-sensitive.- Add a claim named
EmployeeIdif it is not already there, and map it to the directory attribute that holds the student ID.
- On the SAML configuration page, copy the App Federation Metadata Url and send it to your Meadow contact.
- Open Properties and set Assignment required? to No (unless you prefer to restrict SSO to only specific groups; see "Assign production users" in General Instructions).