Skip to main content

Set Up Single Sign-On (SSO) with Veracross (OpenID Connect)

This guide walks administrators through configuring Single Sign-On (SSO) between Orah and Veracross using OpenID Connect (OIDC), allowing users to log in to Orah using their Veracross credentials.

Updated over a week ago

🧩 Overview

Single Sign-On (SSO) with Veracross enables secure authentication through your school’s Veracross identity provider. Using OpenID Connect (OIDC), users can access Orah without needing separate login credentials.

Why this matters:

  • Simplifies user login experience

  • Centralizes authentication within Veracross

  • Improves security and access management

Applies to:

  • ✅ Admins

  • ✅ IT / Systems Administrators

  • ✅ Schools using Veracross as their SIS


🧭 Step-by-Step Instructions

Step 1: Create an SSO Profile in Orah

  1. Log in to Orah as an administrator

  2. Navigate to Admin Console → Authentication

  3. Click Create New Profile (top right)

  4. Select OIDC as the profile type

  5. Choose which users can log in using this SSO profile

  1. Copy the Redirect URL generated by Orah

  2. Keep this page open — you’ll return after configuring Veracross


Step 2: Configure OAuth Application in Veracross

  1. Navigate to the Identity & Access Management (IAM) homepage in Veracross (Axiom)

  2. Locate the existing OAuth Application created for Orah

  3. Add the required openid scope

    • Only users with the OAuth_App_Admin role can configure this

  4. Register the Redirect URL copied from Orah in the OAuth Application


Step 3: Complete the Setup in Orah

  1. Return to the Orah SSO profile created in Step 1

  2. Enter the Login URL using this format:

  3. Enter the Client ID

  4. Enter the Client Secret

  5. Click Save


Step 4: Test the SSO Connection

  1. Click Test Run in the Orah SSO profile

  2. You’ll be redirected to the Veracross login page (if not already logged in)

  3. Log in using your Veracross credentials

  4. You’ll be redirected back to Orah

  5. A success message confirms the SSO setup is working


💡 Best Practices / Tips

  • Use a dedicated OAuth Application for Orah

  • Ensure the openid scope is always enabled

  • Copy Redirect URLs exactly — no extra characters

  • Test with a non-admin user before rolling out broadly


❓ FAQs

Who can configure Veracross SSO?

A user with the OAuth_App_Admin role in Veracross and an Orah Admin are both required.

Can SSO and standard login both be enabled?

Yes. Schools can allow both methods if desired.

What is the School Route?

It’s your Veracross tenant identifier used in the login URL.


🔧 Troubleshooting

Authentication fails

  • Recopy Client ID and Client Secret

  • Ensure no spaces were added

Redirect URL mismatch

  • Confirm the Redirect URL in Veracross exactly matches Orah

Scope errors

  • Verify the openid scope is enabled

Endpoint / login URL errors

  • Confirm the School Route is correct

  • Ensure the login URL uses the correct format


Additional Resources

Did this answer your question?