The idea
Institution members sign in with the account they already have — the university's identity provider — instead of creating and remembering a separate Folio password. Administrators can configure either OpenID Connect (OIDC) or SAML 2.0 from the institution security settings. Both flows support just-in-time provisioning, so a first verified sign-in creates the membership automatically while preserving Folio's duplicate-account safeguards.
Why it matters
For a campus rollout, a second password is a real barrier — to adoption and to IT approval. SSO means no credentials to reset, access that follows someone's university account when they leave, and one fewer thing for a security review to flag. For most institutions this is the difference between "we'll pilot it" and "we'll deploy it."
Where we are
OIDC and SAML 2.0 are available for institution tenants. SAML administrators can provide an identity-provider metadata URL or enter the entity ID, SSO URL, and signing certificate manually. Folio passes signing material directly to its managed authentication provider and does not retain the certificate in the application database or audit log.
Before enabling SSO for everyone, use the built-in test sign-in and confirm the identity-provider assignment with your institution's IT team.