Set Up Your Identity Provider in Foundry
Learn how to set up your Identity Provider in Foundry
Before you begin, make sure you’ve completed the Pre-Implementation Checklist. Once you’ve gathered the necessary information about your identity provider (IDP), follow the steps below to configure it in Foundry.
1. Log in to Foundry
Use the URL provided by your Everfi representative. You must already have a user profile in the system to proceed.
2. Navigate to Single Sign-On Settings
In the left navigation, go to Settings > Single Sign-On.
If you don’t see this option, your account may not have SSO enabled yet. Please contact Support for assistance.
3. Access Everfi SAML Metadata
Click View next to Everfi SAML Metadata, then either:
- Select Download Full Metadata, or
- Scroll down and click Download encryption certificate
Close the modal when finished.
4. Add a New Identity Provider
Click New Identity Provider in the top-right corner to begin creating your SSO configuration.
5. Enter Display Name
Provide a Display Name—this is what learners will see on the Foundry login page.
6. Configure Login Behavior
Choose your preferences for the following options:
-
Allow service provider initiated login?
Check this box to allow SP-initiated SSO (users start login from Foundry). -
Also log users out of this provider when logging out of Foundry
Check this box to enable single logout (SLO). -
Suppress Welcome Email to users on first login via SSO?
Check this box if you don’t want users to receive a welcome email when they log in via SSO for the first time.
7. Use the Everfi SAML Certificate
The Everfi SAML Certificate will be selected automatically. This ensures the most current certificate is used.
8. Choose a Signing Algorithm
Select your preferred Signing Algorithm:
- SHA-256 (default and recommended)
- SHA-1 (only if required by your IDP)
9. Add a Technical Contact
Provide a name, phone number, and/or email address. This contact will:
- Be shown to learners if they encounter SSO errors
- Receive notifications from Everfi about SSO issues (e.g., expiring certificates)
10. Enter SSO Metadata
Provide your IDP’s metadata using one of the following methods:
-
Use a URL – Enter the SAML metadata URL
-
Upload XML Data – Upload your IDP’s metadata file
-
Enter Parameters in a Form – Manually enter the following:
- Entity ID – Your IDP’s unique identifier
- Single Sign-On (SSO) URL – Login URL
- Single Logout (SLO) URL – Logout URL (if applicable)
- IDP Certificate Algorithm and Fingerprint, or
- IDP Certificate Text – Paste the full encoded certificate text
11. Enable Just-In-Time (JIT) User Provisioning (Optional)
If you want to provision users automatically during SSO, enable Just-In-Time User Provisioning.
See this article for full configuration steps.
12. Save Your Configuration
Click Save to complete your SSO setup.