Overview
The FUYL™ Smart Locker System offers seamless authentication via Single Sign-On (SSO), allowing users to access the system using their organizational Identity Provider (IdP). This method simplifies access management by relying on the organization’s IdP, which handles all user accounts and credentials. The FUYL Smart Locker System is compatible with most IdPs that support SAML or OIDC protocols.
It is recommended to comprehensively plan your intended IdP and Provisioning configuration before implementing.
How SSO works
- Select the login option On the FUYL Portal or FUYL Kiosk.
- Redirect to the IdP The user is redirected to the Identity Provider’s authentication screen (e.g., Google Workspace).
- Enter credentials The user enters their credentials.
- IdP verifies The IdP verifies the credentials and sends a response to the FUYL System.
- Access granted The FUYL System grants the user access.
Note: SSO and provisioning features are supported by WorkOS, an Enterprise Identity Management solution.
If your Admin Profile's domain differs from the domain for which you wish to configure SSO, please contact support with the additional domain before beginning this guide.
Set up SSO
Setting up SSO for FUYL Enhanced is a straightforward process managed through the FUYL Portal. IT Admins can select an Identity Provider and follow a convenient step-by-step wizard designed to provide instructions specific to their selected provider.
Some examples of supported Identity Providers include:
| Auth0 | ADP OpenID Connect | CAS SAML |
| ClassLink | Clever** | Cloudflare |
| CyberArk SAML | Duo | Entra ID (formerly Microsoft Azure AD) |
| Google SAML* | JumpCloud | Keycloak |
| LastPass | Login.gov | Microsoft Active Directory Federation Services |
| miniOrange | NetIQ | Okta |
| OneLogin | Oracle | PingFederate |
| PingOne | Rippling | Salesforce |
| Shibboleth Generic | Shibboleth Unsolicited | SimpleSAMLphp |
| VMWare |
*Google Workspace connections may take up to 24 hours to propagate, and may show as inactive in that time
** To integrate with Clever, IT Admins must contact support to provide details such as the Clever domain and ensure the SSO domain matches the Portal domain. Integration allows users to log in using methods like Clever badges, emoji logins, or usernames.
If your identity provider is not listed above, you can connect to SSO using a custom SAML or ODIC connection.
Process
- Open Settings > Users In the FUYL.io Portal. The settings button is in the bottom left of the FUYL Portal interface.
- Configure Single Sign On Select Configure in the Single Sign On tile.
- Choose the Identity Provider From the list, or select Custom SAML or Custom OIDC for providers that aren’t listed.
- Follow the instructions Tailored to your chosen provider.
- Save and test Save and test the connection.
Set Up Provisioning
While SSO outsources authentication to a chosen external Identity Provider, some features of the FUYL Smart Locker system rely on a greater level of synchronization to simplify the user experience (e.g. Login ID or Admin selection).
The FUYL Smart Locker System leverages SCIM (System for Cross-domain Identity Management) or SFTP to automate identity provisioning, updates and de-provisioning of users. Provisioning gives IT Admins greater control over user access by defining schema and attribute mapping.
Process
Ensure that SSO is set up and working before beginning provisioning set up.
- Open Settings > Users In the FUYL.io Portal. The settings button is in the bottom left of the FUYL Portal interface.
- Configure Provisioning Select Configure in the Provisioning tile.
- Follow the instructions You’ll be directed to tailored instructions for your IdP or SFTP.
- Check the users Once set up, check the users exist in the Users tab. Users may take several minutes to propagate, especially in larger directories.
Admin Selection
Provisioning allows the original FUYL Portal admin to view and assign other FUYL admins from a list of synced SSO users in the FUYL Portal interface.
See Managing User Roles below for more information
Login ID
Login ID allows users to authenticate with a single attribute, such as Student ID, Barcode or a Lunch Code.
See the Login ID Set Up guide here
RFID
RFID allows users to authenticate by tapping a compatible card or fob.
See the RFID Authentication guide here.
Managing User Roles
By default, users authenticated through SSO have access to identify at the FUYL Kiosk, but specific workflows can be configured to authorise access (eg, Student Loans could be restricted to members of a "student" group)
Administrators can be promoted from FUYL users or invited separately.
Assigning Admin Roles
- Open the Admins page In the Settings section.
- Click Assign User And search for the user in the directory.
- Select the user To assign admin privileges, or select Invite new user if they’re not already present.