Your students sign in with their school account
No new password: students type their school address, authenticate with you, and land on toGaether already attached to the institution.

Three screens, no more
The student types their school address
toGaether recognises the domain (for example @student.your-school.fr) and knows it belongs to your institution.
They authenticate with you
They are sent to your directory's sign-in page, with your rules: two-factor authentication, password policy, access conditions.
They come back signed in and attached
Their account is attached to the school without manual approval. If they already had an account, that is the account they get back, with their associations and roles.
Works with your directory
Two standards cover almost every institution. If your identity provider speaks either one, it works with toGaether.
- SAML 2.0
- Shibboleth, LemonLDAP::NG, ADFS, and academic federation identity providers.
- OpenID Connect
- Microsoft Entra ID, Google Workspace, Okta, Keycloak and any standard OIDC provider.
What your IT team keeps in hand
Setup
We configure the connection with your IT team. We need:
your identity provider's metadata (SAML) or its issuer and a client ID (OIDC);
the list of the institution's email domains;
a test account to validate the flow before opening it.
In return, we send you what to declare on the directory side (service identifier, return URL).
SSO is set up with your IT team
Tell us which identity provider your institution uses: we reply within one business day.