What is Single Sign On (SSO)?
SSO allows schools to use their existing identity management solution for users to authenticate and sign into GiveCampus.
DGH">Who can leverage SSO on GiveCampus?
To understand if you can leverage Single Sign On on GiveCampus, you’ll need to answer two questions.
-
Is SSO part of my GiveCampus Plan?
Reach out to your Partner Success Manager to see if SSO is part of your plan!
-
Who should be able to sign in using SSO?
You can decide to enable SSO for your Volunteers within GC Volunteer Management or for Administrators platform wide. Note: Enabling SSO for Volunteers in the VMS does not impact the advocate login experience.
Interested in adding SSO to your GiveCampus Platform Plan? Reach out to your partner success manager.
How to Enable SSO:
GiveCampus supports two SSO paths: a WorkOS-managed connection and a legacy SAML metadata form. New schools are configured with WorkOS by default. Schools that previously entered legacy SAML metadata will continue to use that method.
setting up sso through workos
If your school’s SSO is managed through WorkOS, the Authentication Settings page displays a Single Sign-On (WorkOS) section instead of the legacy SAML form. To access this page, navigate to Home > Settings > Authentication Settings or visit https://www.givecampus.com/schools/[school_name]/dashboard/authentication_settings.
In the Single Sign-On (WorkOS) section you will see:
- Connection status – displays one of the following: Active, Pending testing, Setup incomplete, Disabled, Deleting, or Unknown. This indicates the health of your WorkOS connection.
- Require Gift Officers to sign in with SAML – available for schools with GC Gift Officer access.
- Require Volunteers to sign in with SAML – available for schools with Volunteer Management access.
- Volunteer Login Button Text: This is the text for the button that volunteers click on your branded GiveCampus login page to initiate the single sign-on process. Note: This field is only available for schools using the legacy SAML metadata form. Schools configured through WorkOS only have the Admin Login button text field.
- Configure SSO in WorkOS – a button that opens the WorkOS admin portal in a new browser tab, where you can manage identity provider metadata, certificates, and attribute mapping. This button appears only once your WorkOS organization has been provisioned.
Note: The Log in with SSO button appears on your admin login page only when SAML is enabled under Admin Log in options on the Authentication Settings page. If the button does not appear after configuring WorkOS, verify that SAML is enabled in the Login Options section and save your settings.
Depending on your GiveCampus plan, the SAML Authentication section may also include:
Go to Home > Settings > Authentication Settings.
If your school is new and has not yet entered any legacy SAML metadata, you’ll see a setup prompt that instructs you to contact GiveCampus support to provision your WorkOS connection. Once set up, you can complete your identity provider configuration via the WorkOS admin portal.
VMS Unit Schools and Inherited SSO
If your school is part of a Volunteer Management System (VMS) as a unit school under a system/parent school, SSO is inherited from the system school's WorkOS configuration.
What unit-school admins will see in the admin UI
-
Authentication Settings page messaging
- The page shows that SSO is inherited. The message states: "Single sign-on for [your school] is inherited from [system school]. To change this connection, please reach out to GiveCampus support."
-
Live connection status
- The page displays a Connection status label (Active, Pending testing, Setup incomplete, Disabled, Deleting, or Unknown) reflecting the system school's status.
-
No unit-level WorkOS configuration
- The Configure SSO in WorkOS button and setup prompt are not shown; the system school’s configuration applies.
-
Login page behavior
- The unit school’s admin login page features the Log in with SSO button at the normal URL, with no separate configuration required.
-
SAML Authentication toggles
- Once inherited, SAML toggles such as Require Administrators to sign in with SAML become available and are managed on the unit school's Authentication Settings page.
Important details and edge cases
- Precedence: If a unit school enters its own identity provider settings, that configuration takes precedence over the inherited connection.
- Changing the inherited connection: Unit-school admins cannot modify the inherited connection. To update it, coordinate with the system-school administrators or contact GiveCampus support as outlined above.
- Visibility and troubleshooting: The inherited connection status is visible on the unit school’s Authentication Settings page and follows the same troubleshooting steps as the primary connection.
additional notes
- When WorkOS SSO is active, the legacy SAML login button is hidden on the admin login page and replaced by the WorkOS SSO button (labeled Log in with SSO by default).
- Schools using legacy SAML metadata continue to see the legacy form on the Authentication Settings page. The WorkOS and legacy sections are mutually exclusive.
- If you encounter errors during a WorkOS SSO login (for instance, if the user cannot be matched or provisioned), an error message will display on the admin login page.
GiveCampus utilizes the SAML protocol to support SSO. Enabling SSO is a two step process that will likely require collaboration with your IT department. Once the required identity provider information has been provided, single sign-on should begin working immediately on your GiveCampus branded login page. Please email support@givecampus.com if you have any questions.
Step 1: Import GiveCampus SAML into your existing identity management solution.
Please refer to https://www.givecampus.com/auth/saml/metadata?uuid=SCHOOLNAME for the GiveCampus SAML metadata that will need to be imported into your existing identity management solution.
FAQ — What is the "UUID" in the metadata URL and where do I find it?
Q: The metadata URL uses a value called "UUID" (for example: https://www.givecampus.com/auth/saml/metadata?uuid=YOUR_UUID). What is that value and where do I find it?
A: The UUID in the metadata URL is the exact value in the UUID field on your Authentication Settings page. It is not your school's display name. Use the value shown (character-for-character) when replacing YOUR_UUID in the metadata URL.
How to find the UUID in the GiveCampus admin UI
- Open the Authentication Settings page: Home > Settings > Authentication Settings.
- Alternatively, access it directly at
https://www.givecampus.com/schools/[school_name]/dashboard/authentication_settings(replace[school_name]with your school's URL slug). - Scroll to the SAML Identity Provider section and locate the UUID field.
Quick notes and gotchas
- The UUID is often set to your school's URL slug (for example,
exampleschool), but always use the value shown in the UUID field. - Import the metadata URL as:
https://www.givecampus.com/auth/saml/metadata?uuid=YOUR_UUID, substituting YOUR_UUID with the exact value from the Authentication Settings page. - If your school shares an identity provider with another institution, the SAML Identity Provider section may display an informational message instead of editable fields.
- A message such as, "SAML Identity Provider is linked to your institution through [school name]..." indicates that your UUID cannot be edited directly. In this case, contact your GiveCampus representative for assistance.
If you can't find the Authentication Settings page
The Authentication Settings page appears only when SSO is enabled for your account. If the page is missing or the direct URL redirects, please refer to the Why the Authentication page might be missing section above. Once access is available, return to Home > Settings > Authentication Settings to locate the UUID field.
Step 2: Add metadata from your existing identity management solution into GiveCampus.
To enter this information, visit your School Dashboard > Settings > Authentication. This page will also let you configure which login options are presented to volunteers and administrators on your branded GiveCampus login page. Metadata requirements are described in detail below.
Enabling the "SSO Required for Admins" setting
Once your SSO configuration is complete and tested, you can require all administrators to sign in using SAML.
How to enable the setting
-
Navigate to Authentication Settings
- Scroll to the SAML Authentication section.
-
Enable the requirement
- Check the box labeled "Require Administrators to sign in with SAML".
- Save your settings.
-
Verify the change
- Test the administrator sign-in at:
https://www.givecampus.com/schools/[school_name]/admin/login. - Confirm that administrators are redirected to your SSO provider.
- Test the administrator sign-in at:
Pre-enablement checklist
Before enabling this setting, ensure that:
- SSO is included in your GiveCampus plan (see the "Who can leverage SSO on GiveCampus?" section above).
- Your SSO configuration has been fully tested with a successful SAML round-trip and valid SAML attributes and certificate.
- Administrator accounts are registered with the exact email addresses sent by your identity provider (see the "New administrators: complete registration before using SSO" section).
- Your IdP configuration is verified, including email/name identifier format, certificate validity, and Single Logout URL behavior.
After enabling
Once enabled, administrators must authenticate through your institution’s SSO provider. If issues arise, then:
- Confirm that the email address in GiveCampus matches the one provided by your IdP.
- Check that administrator permissions are active.
- Refer to the troubleshooting guidance in the "Troubleshooting SSO error messages" section above.
Required Fields:
- Admin Login Button Text: This is the text for the button that administrators will click on your branded GiveCampus login page to initiate the single sign-on process. ("Log in with SSO" is used in the screenshot below in the 'Login Options' section!)
- Name (of SSO solution): This is the name you use to refer to your existing identity management solution (e.g., “Shibboleth”).
- IDP Metadata Endpoint: This is a URL hosted within your school’s internal IT infrastructure that provides metadata about your institution’s existing identity management solution.
- UUID: When GiveCampus receives a successful SAML login response back from a partner institution, we use this UUID field in order to pair the user with the correct identity provider within our system.
- IDP Entity: We recommend setting this field to https://www.givecampus.com
- Single Sign-on URL: This is the URL within your internal IT infrastructure that GiveCampus will redirect your volunteers and administrators to when they click the login button on your branded GiveCampus login page.
- Name Identifier Format: This is the format for the user’s name and email address in the SAML response you send back to GiveCampus after a successful login attempt. We recommend using the urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress format, but have provided the configuration option on the off-chance your team needs to override it.
- Certificate (in PEM format): This is a public key provided by your institution in order to facilitate secure authentication communication between both parties.
- Single Logout URL: When logging out of GiveCampus, this URL gets triggered behind-the-scenes in order to end the user’s session within your institution’s existing identity management solution.
Login Options
Once SSO is configured you can customize the login options your administrators will see. In order to login to SSO and see these configuration options, admins will need to visit your admin login page at https://www.givecampus.com/schools/[school_name]/admin/login.
The below options will allows you to enable or disable each of these items on your login page:
IDP Specific Configurations
Microsoft Entra ID
To connect Microsoft Entra (and most other SSO providers) you'll need to modify a 'Claim Name' in your Microsoft settings. Please update the 'Claim Name' for the 'Value' "user.mail" to "email".
Matching your settings to these screenshots should ensure a successful connection.
FAQ — Common IT Questions on SSO
Q: Does GiveCampus support SCIM (System for Cross‑domain Identity Management) for automated user provisioning?
A: No. All administrator and volunteer accounts must be created and managed manually via the GiveCampus admin interface. Include manual provisioning in your SSO rollout plan.
Q: Is GiveCampus published in the Microsoft Entra ID (Azure AD) Enterprise App Gallery?
A: No. Because GiveCampus is not listed in the gallery, Entra ID admins must create a custom SAML enterprise application. In the Entra UI, choose Create your own application and select Integrate any other application you don't find in the gallery (Non-gallery). Then follow the SAML configuration steps in the "IDP Specific Configurations > Microsoft Entra ID" section (including changing the Claim Name for the Value "user.mail" to "email").
Q: What should Entra ID admins consider when setting up SAML?
A few key points:
- Select the non-gallery (custom) application path and enter the GiveCampus SAML metadata/UUID exactly as shown on your Authentication Settings page.
- Update the Claim Name from "user.mail" to "email" so that GiveCampus receives the expected attribute.
- Ensure that the email provided by your identity provider exactly matches the GiveCampus administrator record. A mismatch will cause sign-in failures.
- Plan for manual provisioning of new admins and volunteers since automated SCIM provisioning is not available.


Why the Authentication page might be missing
If you don’t see the Authentication section under School Dashboard > Settings (or the direct URL returns an error or redirects you away), that visibility is controlled by a feature flag called school_level_saml_authentication. When that feature flag is not enabled for your school, the Authentication section will not appear in School Dashboard > Settings.
Only GiveCampus support can enable the school_level_saml_authentication feature flag for your account. If the flag is not enabled, you will not be able to reach the Authentication settings from the dashboard UI or by visiting the direct URL.
What to do next
- Confirm SSO is included in your GiveCampus plan by checking with your Partner Success Manager. SSO must be part of your plan before the flag should be enabled.
- Request that GiveCampus enable the school_level_saml_authentication feature flag by emailing support@givecampus.com. When you contact support, include:
- Your school name and your school slug (the value used in your GiveCampus URLs)
- The email address(es) of the administrator(s) who need access
- Whether you intend to enable SSO for Administrators, Volunteers, or both
- Any partner or onboarding contact you’ve been working with (Partner Success Manager)
- After GiveCampus support confirms the feature flag has been enabled, refresh your School Dashboard and open School Dashboard > Settings > Authentication to continue SSO configuration. If the Authentication page still does not appear, confirm that the administrator account trying to view it has the necessary administrative permissions (see the article’s permissions checklist).
Quick troubleshooting notes and gotchas
- If the direct URL returns a “not found” or redirects, that is a strong indicator the school_level_saml_authentication flag is not enabled for your account.
- Enabling the flag is an account-level change and may take a short time to propagate; wait a few minutes, then refresh the dashboard after support confirms the change.
- The article’s existing guidance about confirming administrative permissions and completing new‑admin registration still applies once the Authentication page becomes visible.
Troubleshooting SSO error messages
Error messages during the SSO authentication process generally come from your school’s identity provider (IdP), not GiveCampus. This is common when you click the SSO login button and receive an error before being redirected back to GiveCampus.
FAQ — I complete SSO at my IdP but get stuck in a redirect loop
If administrators authenticate successfully at your identity provider (IdP) but are immediately sent back to the GiveCampus login page in a continuous cycle, this indicates that the SAML response cannot be matched to a known administrator record. This is typically caused by one of two issues:
-
Email mismatch: The SAML response email must exactly match the email on the GiveCampus administrator record. If the emails differ (even slightly), the callback fails to match the account and the login page reloads.
-
Cached session auto-redirect: If an administrator was already logged in using email and password when SSO was enabled, GiveCampus will automatically redirect that session through SAML on the next admin-page visit. If the SAML response’s email does not match the stored admin record, the redirect loop occurs.
Diagnostic steps:
- Open a private/incognito browser to clear any cached session state. This step helps isolate issues related to auto-redirect.
- Verify that the email address on the GiveCampus administrator record exactly matches the email sent by the IdP (character-for-character).
Recovery steps:
-
Disable the SSO requirement temporarily:
- Navigate to School Dashboard > Settings > Authentication Settings.
- In the SAML Authentication section, uncheck the box labeled "Require Administrators to sign in with SAML." and save your changes.
-
Have affected administrators sign in using the standard email/password method so they can access and update their profile email.
-
Align emails:
- Ensure each administrator’s GiveCampus email exactly matches the email sent by the IdP. If the UI does not permit editing, contact GiveCampus engineering to update the records.
-
Test a full SAML round-trip:
- Using a fresh private/incognito window, go to
https://www.givecampus.com/schools/[school_name]/admin/loginand use the SSO button to perform a complete sign-in. Confirm that the admin can access the dashboard without encountering a redirect loop.
- Using a fresh private/incognito window, go to
-
Re-enable the SSO requirement:
- Once one administrator successfully completes a full SAML sign-in, re-check the "Require Administrators to sign in with SAML" option in Authentication Settings and save your changes.
Why toggling the requirement works:
Disabling the SSO requirement allows administrators to log in via email/password so they can correct any email mismatches. With the requirement off, there’s no forced SAML redirect, which prevents the loop while you resolve the issue.
Before re-enabling SSO, confirm that:
- Every administrator’s GiveCampus email exactly matches the IdP-provided email.
- At least one administrator has completed a full SAML sign-in from a fresh browser session without looping.
- The SAML configuration details (certificate, Single Sign-on URL, Name Identifier Format) are up-to-date.
Additional notes:
- Testing in private or incognito mode is essential to avoid issues with cached sessions.
- An error message stating that an administrator record is missing indicates an email mismatch. Correct the email mapping, then re-test the SAML sign-in.
When to escalate to engineering:
If the emails are aligned and you still experience a loop, document a successful test timestamp, note an affected administrator’s email, and capture the IdP's SAML attribute mapping. This information will help GiveCampus engineering investigate the SAML callback matching process.
re-enable the SSO requirement.Identifying the source of the error
- Error on the school's login page or IdP screen (before returning to GiveCampus): Contact your internal IT team.
- Successful IdP authentication but restricted access in GiveCampus: Verify that your GiveCampus administrator permissions are correctly configured.
Administrator provisioning checklist
- Account presence: Ensure that you’re using the same email from your IdP as the email address account on Zendesk. Some organizations use a specific email for SSO that is different than the vanity email you might share. You’ll need your GiveCampus account to match the SSO email address.
- Proper permissions: Confirm that the IdP role or entitlement mapped to GiveCampus is active and has not expired.
If you still can’t sign in
-
Confirm login options: Check if the standard email/password login is available at
https://www.givecampus.com/schools/[school_name]/admin/login. - Work with IT: Provide your IT team with a screenshot of the IdP error, the exact time (with time zone), and your email address so they can locate the failed sign‐in attempt.
Required permissions:
- SSO must be enabled for your GiveCampus plan
- Administrative access to your GiveCampus account
If the page still doesn't load:
- Verify SSO is included in your plan by contacting your Partner Success Manager
- Confirm your account has the necessary administrative permissions
New administrators: complete registration before using SSO
Even if SSO is enabled for your school, new administrators must complete registration via their invitation email before SSO can be used.
- Required registration: Registration must be completed to activate SSO.
- Use the invitation email: Click the registration link provided in your invitation email.
- Email must match: Register using the exact email address that was invited.
First-time setup steps
- Open the invitation email and click the registration link.
- Complete your GiveCampus account setup using the invited email address.
- After registering, visit
https://www.givecampus.com/schools/[school_name]/admin/loginand click your SSO login button.
Didn't receive the invitation email?
- An existing administrator can resend your invitation. Also check your spam folder.
Tip: If you can authenticate with your identity provider but cannot access the admin dashboard, it likely means your registration is incomplete.
Comments
0 comments
Article is closed for comments.