Configuring SAML-Based SSO with Clever

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Clever supports a SAML-based single sign-on (SSO) service for its web-based application that you can configure in your RapidIdentity portal. These configuration settings are an example and may vary for individual configurations.

Requirements
  • Clever district administrator credentials
  • Access to your RapidIdentity administrator portal
  1. Navigate to your RapidIdentity administrator portal.
  2. From the module selector, choose Configuration.
  3. Select Security > Identity Providers > Federation Partners.
  4. Click Add Federation Partner > SAML 2.0, then click Create SAML Relying Party.
  5. In the General section, paste the Clever metadata in the Metadata field.
    Note:

    Remove the validUntil entry, if present.

  6. In the SSO Settings section, configure the settings according to Clever's requirements.
  7. In the Attribute Mapping section, click Add New Attribute + and configure the following LDAP attribute:
    Important:

    Match the case (uppercase/lowercase) exactly when creating LDAP attributes.

    LDAP AttributeSAML NameFriendly NameName FormatName Format Value
    mailclever.any.emailclever.any.emailURI Referenceurn:oasis:names:tc:SAML:2.0:attrname-format:uri
  8. Set the following attribute permissions:
    NamePermit/Deny
    clever.any.emailPermit
    SAML Transient IDDeny
  9. Click Create, then click Save.

RapidIdentity and Clever are now integrated, allowing users to authenticate to Clever with their RapidIdentity credentials.