ignore

Want to build your own 24/7 FAQ knowledge base?
LibraryH3lp subscriptions include unlimited independent internal or public-facing knowledge bases.


Search the LibraryH3lp Knowledge Base

 

How do I set up SSO?

16 views   |   Last updated on Oct 07, 2026    single sign-on SSO

 

Make sure SSO is enabled on your account

If you have a new trial account, SSO should be enabled by default.  You should be all set.

If you have an older account, we need to enable SSO for you.  Send an email to us at support@libraryh3lp.com and we'll enable that for you to try.

 

Head to the admin dashboard, Accounts page

SSO is configured in the Accounts page in the dashboard. The accounts page has a dollar sign icon in the left navbar.  From there, look for an "Authentication" area that is available to users in your Administrators group.

The "Add My Provider" button opens a dialog for setting your Identity Provider (IdP) metadata URL and name ID format. 

Our LibraryH3lp SAML Service Provider URL will vary based on your service region (main, EU, CA, SG).  It is needed to configure things on your end in the Identity Provider (IdP).

Requirements

Any SAML-based single sign-on (SSO) system should work.  This includes Shibboleth and most Active Directory implementations, as long as they support SAML. 

Your Identity Provider (IdP) must release user details to our Service Provider (SP) in a Name Identifier <NameID> element within the SAML <subject> element. 

Your IdP must release an identifier that stays persistent for each user across logins, not one that is transient and will change. 

We are set up for three NameID formats (persistent, emailAddress, and other/custom):
 
1) urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
2) urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
3) "other" which means you can plug in something besides "persistent" or "emailAddress" using the SAML "urn" syntax as seen above.
 

There is a setting that allows you to disable LibraryH3lp native username/password logins if you'd like to do so.  You'd want to make sure that everything was working and your local admin account was set up and working before taking that step.  It would mean that your users could ONLY authenticate using SSO.  If you found yourself locked out at any point, we would be able to get you unstuck through our regular support process.

Optional: custom Display name for your organization

If you'd like something different to display for your users other than your existing "Organization" name as set in your LibraryH3lp subscription details when they sign into LibraryH3lp through SSO, you can change it in the Details tab on the Subscription page.

 

Setting up users in the admin dashboard

Moving on to user configuration, you can make things easier for your users by pre-populating their local email address or other persistent identifier as their SSO identifier in order to link their LibraryH3lp account with their local email account.  This SSO identifier should match the identifier that is getting released by your IdP.

This is available in our users management page in the LibraryH3lp dashboard.

Note that "SSO identifier" is separate from "Email."  In some cases these might be different things.  Email is used in the event of someone using the automated username/password recovery feature for their LibraryH3lp username/password (not SSO).

If you'd like, we can do a one-time copy of existing user emails to SSO identifiers so that you don't have to do that manually on your side for so many users, just send us a support request at support@libraryh3lp.com.

If you do NOT pre-populate the SSO identifier, then your users will make that association and populate it when they first successfully authenticate using SSO.  More on that soon...

 

Signing in via SSO

Users will pick the "Sign in via your institution" option on the login screen.

Users should receive your familiar local login prompt in a new tab.

If their SSO identifier was previously set up in the LibraryH3lp admin dashboard, then they should be signed into LibraryH3lp automatically as the associated LibraryH3lp user.

If their SSO identifier was NOT already set up, then they will be prompted for their LibraryH3lp username and password.  If they are successful with their LibraryH3lp username/password, then their local email address should be linked to their LibraryH3lp credentials as their SSO identifier, and that association should persist so that they do not have to do linkage that again.

Once they have successfully authenticated, they should see a "Success" window and return to Libraryh3lp, now authenticated.

FAQ URL:

More Help

Search By Topic

Chat is offline. Click to email us.