🧩 Overview
Single Sign-On (SSO) with Veracross enables secure authentication through your school’s Veracross identity provider. Using OpenID Connect (OIDC), users can access Orah without needing separate login credentials.
Why this matters:
Simplifies user login experience
Centralizes authentication within Veracross
Improves security and access management
Applies to:
✅ Admins
✅ IT / Systems Administrators
✅ Schools using Veracross as their SIS
🧭 Step-by-Step Instructions
Step 1: Create an SSO Profile in Orah
Log in to Orah as an administrator
Navigate to Admin Console → Authentication
Click Create New Profile (top right)
Select OIDC as the profile type
Choose which users can log in using this SSO profile
Copy the Redirect URL generated by Orah
Example format:
Keep this page open — you’ll return after configuring Veracross
Step 2: Configure OAuth Application in Veracross
Navigate to the Identity & Access Management (IAM) homepage in Veracross (Axiom)
Locate the existing OAuth Application created for Orah
Add the required openid scope
Only users with the OAuth_App_Admin role can configure this
Register the Redirect URL copied from Orah in the OAuth Application
Step 3: Complete the Setup in Orah
Return to the Orah SSO profile created in Step 1
Enter the Login URL using this format:
Enter the Client ID
Enter the Client Secret
Click Save
Step 4: Test the SSO Connection
Click Test Run in the Orah SSO profile
You’ll be redirected to the Veracross login page (if not already logged in)
Log in using your Veracross credentials
You’ll be redirected back to Orah
A success message confirms the SSO setup is working
💡 Best Practices / Tips
Use a dedicated OAuth Application for Orah
Ensure the openid scope is always enabled
Copy Redirect URLs exactly — no extra characters
Test with a non-admin user before rolling out broadly
❓ FAQs
Who can configure Veracross SSO?
A user with the OAuth_App_Admin role in Veracross and an Orah Admin are both required.
Can SSO and standard login both be enabled?
Yes. Schools can allow both methods if desired.
What is the School Route?
It’s your Veracross tenant identifier used in the login URL.
🔧 Troubleshooting
Authentication fails
Recopy Client ID and Client Secret
Ensure no spaces were added
Redirect URL mismatch
Confirm the Redirect URL in Veracross exactly matches Orah
Scope errors
Verify the openid scope is enabled
Endpoint / login URL errors
Confirm the School Route is correct
Ensure the login URL uses the correct format
Additional Resources



