Sign in with the account your organisation already has
Connect your own identity provider to Puzzel.org, over OpenID Connect or SAML 2.0, and the people who play your activities or follow your courses sign in where they always do. Nobody types a name, nobody picks another password, and every result belongs to somebody you know.
For schools and companies that manage their accounts in one place. You set it up yourself, in your dashboard: one address to register with your provider, four fields to fill in, and a test that signs nobody in.
This activity is for people with an account at Acme. Signing in takes you to its sign-in page and straight back here.
- On an activity's own link, before they play
- On your login page and in your classes, with Puzzel LMS
- In an activity embedded in your own portal, without a click
There is no Clever or ClassLink connector, and no automatic provisioning (SCIM): somebody appears when they first sign in, or when you add them. And it signs in the people who play and learn — the people who build activities keep signing in to Puzzel.org with Google, Microsoft or their email address.
How it works
- Register Puzzel.org with your provider Add it as an application there, over OpenID Connect or SAML 2.0, and tell it where to send people back to: OpenID Connect · Redirect address
https://puzzel.org/api/sso/callbackSAML 2.0 · Reply URL (ACS)https://puzzel.org/api/sso/saml/acsSAML 2.0 · Entity ID (audience)https://puzzel.org/api/sso/saml/metadata - Fill in what your provider gives you In your dashboard, under Connected apps: the issuer URL, the client ID and, if there is one, the client secret — or, over SAML, the sign-in URL, the entity ID and the certificate. And the name people will see on the button.
- Test the connection One button takes you to your own sign-in page and back, and tells you who your provider said you are. Nobody is signed in to anything. Setting up and testing is free, on any account.
- Switch it on where you want it Per activity, choose SSO as the only sign-in option. For your courses, choose it as a way to sign in under LMS settings.
Two protocols, one connection
Puzzel.org speaks both of the standards identity providers use. You pick one when you connect; everything after that — who gets in, where people sign in, what a result looks like — is the same.
OpenID Connect
The newer of the two, and the one to choose when your provider offers both: fewer values to exchange and nothing to renew by hand.
- Your provider gets one redirect address
- You fill in an issuer URL, a client ID and usually a client secret
- An activity embedded in your own portal can pass the token along, so nobody clicks at all
SAML 2.0
The standard many organisations have used for years, and sometimes the only one a provider or a policy allows — AD FS and Shibboleth, for example.
- Your provider gets a reply URL and an entity ID
- You give Puzzel.org your provider's metadata: as a link, as a file, or typed in
- The signing certificate has an end date; the card shows it, and you replace it there when your provider renews it
Step by step, for your provider
The first two steps differ per provider and per protocol. The menu names below are the providers' own; they move things around now and then, so tell us if one of them is no longer where we say it is.
Microsoft Entra ID
- In the Microsoft Entra admin center, go to Entra ID → App registrations and choose New registration.
- Name it Puzzel, keep “Single tenant only” under Supported account types, and choose Register.
- Under Authentication, add the platform Web and paste the redirect address.
- Under Certificates & secrets, choose New client secret and copy its Value.
- In Puzzel.org, the issuer URL is https://login.microsoftonline.com/ followed by your Directory (tenant) ID and /v2.0. The client ID is the Application (client) ID.
Entra sends the sign-in name as the address unless you add the optional email claim under Token configuration. Puzzel.org accepts either.
Okta
- In the Okta Admin Console, go to Applications → Applications and choose Create App Integration.
- Choose OIDC - OpenID Connect as the sign-in method and Web Application as the type.
- Keep the grant type Authorization Code and paste the redirect address under Sign-in redirect URIs.
- Under Assignments, choose who may use it, and save.
- In Puzzel.org, the issuer URL is your Okta address, such as https://your-company.okta.com. The Client ID and the Client secret are on the app's General tab.
Somebody the app is not assigned to is turned away by Okta itself. If you use a custom authorization server, its issuer ends in /oauth2/default.
Google Workspace
- In the Google Cloud console, open Google Auth Platform and set it up with the audience Internal, so that only accounts of your organisation can sign in.
- Under Clients, choose Create client and pick Web application.
- Paste the redirect address under Authorized redirect URIs and create the client.
- Copy the Client ID and the Client secret.
- In Puzzel.org, the issuer URL is https://accounts.google.com. Fill in your email domain as well.
With the audience External, any Google account can sign in. The email domains you list in Puzzel.org are then the only fence, so always fill them in.
Another provider
Puzzel.org uses plain OpenID Connect, so a provider that follows it — Keycloak, Auth0, OneLogin, JumpCloud, Ping — connects the same way. You need its issuer URL, a client ID and usually a client secret, the authorization code flow, and the scopes openid, email and profile. A provider or a policy that only allows SAML 2.0, such as AD FS or Shibboleth, connects too: choose SAML 2.0 in your dashboard, register the reply URL and entity ID it shows, and paste your provider's metadata.
You decide who gets in
List your email domains and only addresses at those domains can sign in. With Puzzel LMS, somebody new at one of them can join your list on their first sign-in, without an invitation — or you keep it to the people you added yourself.
What Puzzel.org receives
Your provider's own id for the person, their name and their email address — never a password. A player's name and address are kept with their result; a learner is recognised by the address on your list. An identity only ever exists inside your account.
Free to test, part of four plans
Connecting your provider and testing it is free, on any account, so you know it works before you choose. Signing your people in comes with the School, Ambassador, Academy and Trainer plans, at no extra cost and for as many people as sign in. Plays still count as sessions, as they always do.
Stuck on a field, or on a provider that is not listed?
Tell us which provider you use and what it shows you. We will walk through the connection with you.