Using Self-Service Single Sign-On (SSO)
| IMPORTANT:
Skilljar Starter customers use the SSO configuration described in the Using Self-Service SSO in Skilljar Starter article. |
This article explains how to set up and manage Single Sign-On (SSO) in Skilljar.
Overview
Single Sign-On (SSO) lets learners authenticate and authorize across multiple applications and services with a single set of login credentials. When configured on a training site, SSO provides a streamlined sign-in experience. For example, when a learner signs in to their main business account, SSO allows them to gain access to other linked services, such as Skilljar.
With the SSO self-service feature, admins can set up and manage SSO directly from the Skilljar Dashboard. Admins can offer more than one login method at the same time, including native Skilljar login alongside one or more SSO methods, and control the order in which the methods appear on the sign-in page.
Skilljar supports the following SSO types:
| SSO Type | Description |
|---|---|
| Token Based | To build a custom authentication flow using the Skilljar API, hosts an endpoint that authenticates users and redirects them to Skilljar with a login token. |
| SAML | Using a SAML-compatible identity provider such as Okta, Azure AD, OneLogin, or Salesforce Identity. This is the most common enterprise SSO protocol. |
| OAuth | Using an OAuth 2.0-compatible provider. Skilljar acts as the OAuth client and retrieves user information from your provider's API. |
| ODIC | Using an OpenID Connect (OIDC) compatible provider. Built on OAuth 2.0 with standardized user identity claims, user data fields are pre-populated, making setup simpler. |
| Community | Enable Community SSO to provide a unified login experience for the Community user and Skilljar learners. |
| Skilljar Native Login | Allow learners to sign in with an email address and password managed by Skilljar. Offer native login on its own or alongside one or more SSO methods. |
A domain can have more than one login method active at the same time. When two or more methods are active, the sign-in page displays each method as a separate option, in the order set for each configuration.
Add SSO Configuration
To enable SSO configuration on your domain:
- Open your Skilljar dashboard.
- Expand the Domains & Publishing header on the left, and select Domains.
- Click Domain Settings for the required domain.

- Navigate to SSO Configuration, click Add Configuration. The Add SSO Configuration slide-out panel appears.

- Select one of the following SSO configurations:
- Token Based
- SAML
- OAuth
- OIDC
- Community
- Skilljar Native Login

- Provide the required details for the selected SSO and click Save. The new SSO configuration appears in the SSO Configuration section.
Activate or Deactivate an SSO Configuration
Each SSO configuration includes a toggle switch that controls whether the configuration is active or inactive.
To activate or deactivate an SSO configuration:
- Navigate to the required configuration in the SSO Configuration section.
- Turn on or off the toggle to activate or deactivate. The domain's SSO configuration is updated immediately.

Set up SSO Order
You can configure multiple login methods for a domain and define the order in which they appear on the sign-in page
To set the SSO order:
- Turn on the toggle for each SSO configuration to activate it.
- Click the Edit icon.
- In each configuration, provide the Order number. The number with the lowest value appears first.
When the SSO configurations are active, the sign-in page displays a button for each one, in the order set for each configuration. To reorder the options at any time, edit the Order field on each configuration.
Customize the Login Page
When two or more login methods are active, learners see a sign-in page that lists each method as a separate button, in the order set for each configuration. The page uses the domain theme colors and button styles.
You can edit the button text and optional help text for each login method. The text is localized, so you can set it for each language pack.
To customize the login button text and help text:
- In the left navigation, select Theming > Languages.
- Select the language to edit.
- In the Pages list, under Custom, select mSSO Login Select Page.

- In the Override Text column, enter the text to display for the page heading and the login button text, and optionally the help text above the login button.

- Click Update after entering text for each column.
- Repeat these steps for each additional language pack.
Test an SSO Configuration
To verify an SSO configuration before activation, click the plug icon on the configuration card. A success message appears if the configuration is set up correctly, confirming the SSO connection is ready for activation.

Edit an SSO Configuration
To edit an existing SSO configuration:
- In the Domain Settings, navigate to the SSO Configuration section.
- Click the edit icon. The SSO Configuration slide-out panel appears with your existing settings.

- Make the required changes and click Save. The configuration is updated
Delete an SSO Configuration
Deleting an SSO configuration is permanent and cannot be undone. If the configuration is currently active, deleting it also deactivates SSO on the domain.
To delete an SSO configuration:
- Navigate to the required configuration in the SSO Configuration section.
- Click the remove icon. The confirmation dialog box appears.

- In the confirmation dialog box, click Delete. The configuration is permanently deleted.
Additional Resources
For more information on SSO, refer to the following articles:
- Configuring Token-Based Single Sign-On (SSO)
- Configuring SAML 2.0 for Single Sign-On (SSO)
- Configuring OAuth 2.0 for Single Sign-On (SSO)
- Configuring OpenID Connect for Single Sign-On (SSO)
- Skilljar and Gainsight CC Integration
View our SSO quick tips video on Skilljar Academy.