> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.biginterview.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SAML 2.0 / Shibboleth Integration

As a Service Provider, we offer the possibility of **using** a SAML 2.0 / Shibboleth SSO integration.

To get started, you can have a look at our default metadata file here: https://app.biginterview.com/saml/metadata

*Please note that this metadata file can be adapted if you request different levels of encryption or other customization.*

**The first step would be to give us the URL to your metadata file.**  
Once received, we will set up the endpoint URLs for your integration, connecting them to your subdomain on Big Interview.

You can find the format and endpoint URLs below:  
issuer: [*https://{subdomain}.biginterview.com/saml/metadata*](https://%7Bsubdomain%7D.biginterview.com/saml/metadata)  
name\_identifier\_format: *"urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"* 
assertion\_consumer\_service\_url: https://{subdomain}.biginterview.com/saml/acs

The only fields that we need as user information are email address, first name and last name.

An email address can be associated with only one SSO domain. If a user is already registered through one SSO domain and attempts to access another SSO domain using the same email address, they may encounter a 404 error or be unable to log in. To use a different SSO domain, the user’s account must first be moved to the new domain. A user can access only one account through SSO using the same email address.

After all the endpoints are set up by both Service Provider and Identity Provider, you can go to https://app.biginterview.com/saml/init to initiate the login process.

If users receive a **“Single Sign-On unexpected error,”** ask the school’s IT department to verify that the SSO security certificate and SSO configuration are current in the school’s identity provider.

If the Identity Provider log reports that **validation of the request signature failed**, the school’s IT or Identity Provider administrator should check whether the SAML signing certificate has expired. If the certificate has expired, they should renew it and update the SAML metadata, then retry the SSO login. Certificate renewal and metadata updates are handled by the institution’s IT department.