Learn how to configure a connection to ClassLink via SAML.
Each SSO Identity Provider requires specific information to create and configure a new Connection. Often, the information required to create a Connection will differ by Identity Provider.
To create a ClassLink SAML Connection, you’ll need the Identity Provider Metadata URL that is available from the organization's ClassLink SAML instance.
Start by logging in to your WorkOS dashboard and browse to the “Organizations” tab on the left hand navigation bar.
Select the organization you’d like to configure a ClassLink SAML Connection for, and select “Manually Configure Connection” under “Identity Provider”.
Select “ClassLink SAML” from the Identity Provider dropdown, enter a descriptive name for the connection, and then select the “Create Connection” button.
The SP Metadata link contains a metadata file that the organization can use to set up the SAML integration.
In order to integrate you’ll need the IdP Metadata URL.
Normally, this will come from the organization's IT Management team when they set up your application’s SAML 2.0 configuration in their ClassLink instance. Here’s how to obtain them:
Login to the ClassLink Management Console (CMC), click Single Sign-On and select SAML Console.
Click ADD NEW or COPY EXISTING. Copy Existing contains pre-configured SAML apps which need to be updated to fit your unique settings.
Edit the new application by click the three dots menu icon, and then selecting Edit.
Update the Metadata URL in the ClassLink application settings with the SP Metadata URL provided to you by WorkOS.
Under the “Attribute Mapping” section of the SAML app, map the following four attributes as shown below, and the select “Update”.
Users can automatically be assigned roles within your application by sending their group memberships. To enable this, set up a group attribute statement following the guidance below.
This feature is currently in beta, contact customer support for more information.
To return this information in the attribute statement, map the groups in your identity provider to a SAML attribute named
Copy the IdP Metadata URL from your ClassLink SAML settings and upload it to your WorkOS Connection settings.
In the Connection settings in the WorkOS Dashboard, click “Edit Metadata Configuration”.
Paste the Metadata URL from ClassLink into the “Metadata URL” field and select “Save Metadata Configuration”.
Your Connection will then be linked and good to go!