Meadow

SSO

Meadow supports SAML 2.0 so students and staff can sign in with your identity provider. The basic steps are to exchange metadata and configure two claims. Follow the steps below to complete the integration.

General Instructions

1. Download Meadow's SAML metadata

Your Integration Engineer will send you metadata via email. The metadata file has the information required to configure SSO with your identity provider:

2. Configure your SSO provider

Instructions differ by provider. Create a SAML integration and application for Meadow in your SSO provider, for example Okta, Microsoft Entra (Azure AD), Google Workspace, or Shibboleth.

You can usually upload the SAML metadata file and the provider fills in the SSO parameters. If it does not accept the file, enter Meadow's Entity ID, public certificate, and callback URLs from the metadata by hand.

If your provider requires .pem format, reformat the certificate with openssl or another tool.

3. Confirm claims for email and student ID

Include these claims in the SAML response.

Claim names are case-sensitive.

4. Assign production users

Make sure students and staff who will use Meadow are assigned access to sign in to this application through SSO. We recommend allowing all users to sign in; we will not create accounts based on SSO attempts. Only users already in Meadow will be allowed to log in.

5. Send your federation metadata

Send your Meadow contact the Federation Metadata XML URL or file from your identity provider. For Microsoft Entra, follow Microsoft Entra.

6. Await confirmation from Meadow

Meadow loads your metadata into our system, then enables SSO. We will also create admin accounts for one or more school staff.

7. Test signing in

If you are unable to sign in, send a test student's username and password to your Meadow contact to test from the Meadow side. Do not send credentials for a real student's account.

Microsoft Entra

  1. Go to portal.azure.com.
  2. Open Microsoft Entra ID.
  3. Open Enterprise applications.
  4. Select New application, then Create your own application. Name it "Meadow" or another name you prefer. Choose a non-gallery application.
  5. Select Set up single sign on, then SAML. If the mode is not SAML, choose Change single sign-on mode.
  6. Select Upload metadata file, upload the SAML metadata from Meadow and save. Close the Basic configuration panel.
  7. Open Attributes & Claims. The attribute that holds a student ID varies by directory.
    • emailaddress is usually configured already. Confirm email is included in the SAML response. Claim names are case-sensitive.
    • Add a claim named EmployeeId if it is not already there, and map it to the directory attribute that holds the student ID.
  8. On the SAML configuration page, copy the App Federation Metadata Url and send it to your Meadow contact.
  9. Open Properties and set Assignment required? to No (unless you prefer to restrict SSO to only specific groups; see "Assign production users" in General Instructions).