Skip to main content
Gainsight Inc.

Using Self-Service SSO in Skilljar Starter

This article is intended for Skilljar Starter admins who configure how learners sign in to a Starter domain.

Overview

Single Sign-On (SSO) lets learners sign in to a Starter domain with credentials from an external identity provider, alongside the default email and password login. For Starter domains, SSO is powered by Gainsight Customer Communities (CC), and the learner sign-in page runs on the Community platform.

Admins set up and manage SSO from Domain Settings. A domain can offer the default authentication method together with one or more SSO methods.

Set the Default Authentication Method

Default authentication lets learners sign in with an email address or username and password.

  1. In the left navigation, select Domains & Publishing > Domains.
  2. Locate the domain to configure, then select Domain Settings.
  3. Scroll to the SSO Configuration section.
  4. Under Default authentication method, select the Default authentication checkbox to turn it on. Clear the checkbox to turn it off.

    Image shows the SSO configuration option

Add an SSO Login Method

  1. In the SSO Configuration section, under SSO method, locate the method to add: SAML 2, Open ID, Token, or OAuth2.
  2. Select Install next to the method. The configuration options appear.
  3. Provide the required details for the selected provider, such as the provider URLs and token claims. Required fields are marked with an asterisk.
  4. Under SSO Field Mapping, map the provider's token claims to the Community (CC) fields so learner attributes such as name, email, user ID, and role stay consistent.
  5. Set any options the provider requires, such as Pass token in Authorization Bearer or Preserve manually granted Custom Roles.
  6. Save the configuration. A configured method displays an Enabled label and an Edit option.

Test an SSO Login Method

Test a method from internal testing before turning it on for learners.

  1. Keep the method turned off for end users so the logs reflect internal testing only.
  2. In the method's configuration, select Test log in and complete the sign-in.
  3. Select View test logs to review the results.

Edit or Remove a Method

  • To change a method, select Edit on its card, update the settings, and save.
  • To remove the default authentication method, select the delete icon on its card.

Learner Login Experience

When default authentication and one or more SSO methods are active, learners see a Community-hosted sign-in page that includes:

  • A button for each active SSO method, for example an OAuth sign-in button.
  • A Username or Email field and a Password field for default authentication.
  • A Log in button and, where applicable, a community staff login option.
  • Was this article helpful?