Shibboleth SSO

Turnitin provides Single Sign-On (SSO) support through a standardized integration with Shibboleth SSO.

Shibboleth SSO for Turnitin Originality, Turnitin Similarity, SimCheck, and iThenticate 2.0 will not support any modifications to the default setup.

Getting set up

In order to use Turnitin’s Shibboleth SSO integration, you must raise a ticket with Turnitin support and our team will help you through the setup process. Before you contact us, please read the rest of this guide to learn more about what information is required for the setup.

Federations

If you would like to configure Shibboleth SSO on your account, you must first become a member of a compatible federation.

Below is a list of federations or projects involving Shibboleth or SAML technology provided by the Shibboleth project that we are partnered with. Each federation typically serves a specific community:

  • AAF Federation (Australia)
  • AAI@EduHr (Croatia)
  • DFN-AAI (Germany)
  • EduGain (via InCommon)
  • Feide Federation
  • GakuNin (Japan)
  • Haka Federation (Finland)
  • IDEM (Italy)
  • InCommon
  • Porto Federation (Portugal)
  • SURFConext Federation (Netherlands)
  • SWAMID (Sweden)
  • SWITCH (Switzerland/Europe)
  • UK federation

To set up Shibboleth we will need your Shibboleth Entity ID. This is typically a URL or URN format string, like `https://my-production-shib.thing.edu` or `urn:mace:incommon:thing.edu`.

Contacting Turnitin

If you are a member of a compatible federation and have your Shibboleth Entity ID then you can contact Turnitin to request Shibboleth SSO be set up for your account.

To contact Turnitin, visit our support center to raise a ticket and our team will help you through the setup process.

Users roles

When signing in to Turnitin using Shibboleth SSO, users will automatically be designated the ‘User’ role.

Revoking access

If a user is created through Shibboleth SSO who should not have access to the account, administrator can revoke access by deactivating the user in the Users area.

Deleting the user will not fully revoke access as the user can create a new account using the Shibboleth SSO link. Deactivating the account means that the user's email will no longer be able to be used for access.