Customer SSO
Let your product users enter the academy with the same account, without a second password. The three modes, step-by-step setup, secret rotation, existing accounts and common errors.
Draft · being trialled on pilot workspaces (06/10/2026)
If your academy is part of a product that already has its own users (for example a software that opens its academy on academy.product.com), with Customer SSO those users enter the academy with their product account: no sign-up on Aladia and no second password. The product signs a token (a JWT) and passes it to Aladia; Aladia verifies the token, creates or updates the account, enrolls it in courses and opens the session.
Owners and admins set it up in Settings > Access and security. It needs the Pro or Enterprise plan; with a smaller plan the section shows a lock and a link to Plans. It works on the name.aladia.io address and on the custom domain (see Domain and email).
When to use it
- Your product already has a login and users, and the academy is part of it: customers should get in with one click from the product.
- You want the product to decide who is a student or a teacher and which courses they access.
If your students sign up to the academy directly, you do not need it: stay on Aladia only.
The three modes
| Mode | What happens |
|---|---|
| Only from your product | Students and teachers enter only from your product. There is no sign-up on the academy site, and visitors without a session go to the product login. |
| Mixed | Sign-in from your product plus direct sign-up and login on Aladia as today. |
| Aladia only (default) | As today: email and password or Google. SSO is off. |
In every mode owners, admins and teachers of the workspace can always sign in with their Aladia account from the academy /login page (for example https://academy.product.com/login): it is the emergency access, even if the product is down. Nothing changes on app.aladia.io.
Setup, step by step
Choose how the token is signed
In Token signature:
- Secret (HS256), the simplest: press Generate secret. Aladia creates one and shows it only once, with its id (
kid). Copy it and give it to your product developers, who store it on the server. Afterwards you only see the last characters here (••••AbCd). - Public key or JWKS URL (RS256 or ES256): if the product signs with its own private key, paste the public key or the address of its JWKS.
Enter the product addresses
In Your product:
- Product login URL: where to send visitors who reach the academy without a session. Aladia adds
return_to, so after the login the user goes back to the page they wanted. Required for Only from your product. - Logout URL (optional): where to take the user after Log out on Aladia.
Test a token
Your product developers generate a test token; paste it in Test a token and press Verify. Aladia checks everything as in a real sign-in (signature, algorithm, audience, expiry, single use, data) and tells you what is wrong, but signs nobody in and does not consume the token.
Turn SSO on
In Sign-in mode choose Mixed (to try it calmly) or Only from your product. The two modes can be selected only once the signature is set up.
Give the sign-in address to your product
In Sign-in mode you find the Sign-in address for your product, https://<your academy>/sso, with a Copy button: it is where the product sends its users. All the details for developers are in the developer guide.
Changing the secret
Regenerate creates a new secret, with a new kid. The previous one keeps working for 24 hours, so the product can switch to the new one without locking anyone out; the row of the previous secret says until when it is valid.
- Revoke now, on the row of the previous secret, turns it off immediately.
- If you think the secret got into the wrong hands: Regenerate with Revoke the current secret now on. Sign-ins signed with the old one fail straight away.
You can regenerate at most 10 times an hour.
What happens to accounts
- First sign-in from the product: Aladia creates an already verified account, without a password, with the product's first and last name, and adds it to the academy as a Student (or Member, if the product marks it as a teacher). Names are updated at every sign-in.
- Aladia account with the same email: Aladia never links them on its own.
- With Allow linking to existing Aladia accounts off (default), it creates a separate account, valid for your academy only.
- On, the user sees Link your account and confirms with their Aladia password; from then on they enter from the product with that account and keep their usual courses. Whoever forgot the password resets it with "Forgot password?" and tries again.
- Accounts created by SSO enter only from the product: they have no Aladia password and "Forgot password?" does not apply to them.
- Roles: the product can only say student or teacher. Admins and Owners are assigned in People, never from the product. A teacher is never turned back into a student automatically: permissions are removed from People.
- Courses and teams: the product can enroll users in academy courses and, for teachers, in teams. A course that is not in the academy does not block the sign-in: you find it among the log warnings.
Sign-in log
Recent SSO sign-ins shows the last 50 sign-ins from the product, successful or not: date, user id in the product, email, outcome (account created, linked, signed in) or error code with the detail, and the warnings about courses and teams. The log keeps 90 days and never contains tokens or secrets.
Log out
With a Logout URL, after Log out the user lands there (for example to log out of the product too). Without it, in Only from your product they land on the academy login; in Mixed on the showcase or the login, as today. Logging out of the product does not log out of the academy.
Common errors
Whoever cannot get in sees Sign-in failed with a code. The most frequent:
| Code | What it means | What to do |
|---|---|---|
jti_reused | the sign-in link was already used | enter again from the product: each link works once |
token_expired | the link expired (it lasts 2–5 minutes) | enter again from the product |
signature_invalid, kid_unknown | the product uses a wrong or old secret | check the secret and the kid in the product; after a rotation, update them within 24 hours |
aud_mismatch | the token is for another address | in the product, aud must be the academy address |
sso_disabled | the mode is Aladia only | choose Mixed or Only from your product |
iat_in_future | the product server clock is ahead | sync it |
role_not_allowed | the product asked for a role that is not allowed | only student or teacher |
The full list, with fixes for developers, is in the developer guide.
Not there yet
- The Aladia mobile app does not use Customer SSO yet: it applies to the academy website.
- Linking is confirmed with the password; the email code comes later.
- Two-step verification for admins and staff SSO (SAML/OIDC) are in the next phases.