Attributes

The current iThenticate Shibboleth configuration requires the following information and released attributes:

  • Your IdP identifier (Shib-Identity-Provider)

    This will typically be a URL.
  • The federation that your institution belongs to

    We currently exchange metadata with many federations and this will be the easiest and fastest way to integrate with iThenticate.

    In some cases we will use an institution's metadata directly. If integrating directly with your IdP, we require your IdP metadata URL and the public key if the metadata is signed. The Turnitin/iThenticate metadata can be found at  https://shibboleth.turnitin.com/Shibboleth.sso/Metadata
  • The attribute that you use to uniquely identify users on your system

    This should never change. For example, ePPN or targeted-id.
  • Attributes for first name, last name, and email address

    These are for user interface display purpose only and are never released to any third-party. You should provide the following:
  • givenName

    This is the user’s first name; if a name is not provided, this will default to “iThenticate”.
  • sn

    This is the user’s last name; if a name is not provided, this will default to “User”.
  • mail  

    This is an email address where the user may receive emails. If a valid email is not provided, an inactive (for example, @example.com) email address will be created as a placeholder.
  • Optional setting to control access. Typically this is isMemberOf.