Students from another institution who only take one or a few courses at your institution can sign in to Ans with their eduID. You add them as external users with their eduID, and they sign in through SURFconext.
eduID is a free account from SURF that anyone can create. It is intended for students who do not have a regular account at your institution, such as exchange students or minor students from another institution. For students from your own institution, continue using the existing attributes, such as uid, email, or student_number.
Although it is technically possible to use an eduID for a regular student account, this is not recommended. An eduID is linked to the student's personal email address rather than their institutional email address. In addition, the eduID identifier is different for each institution. This means that the same student receives a different eduID identifier for each institution where they use eduID.
By adding these students as external users, they can take your exams in Ans without needing a regular account at your institution.
Before you start
You need four things in place:
- The custom SAML identity provider feature. It is part of the Collaborate plan. Is it not active for your school? Ask our support team to turn it on.
- A SURFconext connection for Ans with eduID enabled. Your IAM team sets this up in the SURFconext dashboard, so the eduID option shows up when students sign in.
- School administrator rights in Ans. You need these to add an identity provider and to create API tokens.
-
The eduID of each student. This is the eduID identifier for your institution, which SURFconext sends as the
urn:mace:eduid.nl:1.1attribute. Your SIS or IAM system usually receives it when the student enrolls.
Step 1: Add SURFconext as an identity provider
- Go to Settings > Authentication.
- Under SSO identity provider, click New identity provider.
- Enter a School name. Students see this name on the sign-in screen, so pick one they recognize, such as your institution's name.
- Enter the Metadata url of your IdP. For SURFconext production, this is
https://metadata.surfconext.nl/idp-metadata.xml. - Click Create.
You can also turn on Prevent Single Sign-On from creating accounts on the same page. Ans then signs in only students who already have an account, so an unknown eduID gets no new one. This setting applies to every SSO sign-in at your school, so only use it if all accounts are already created through your SIS or the API.
For more about identity providers, see Single Sign-On with SAML.
Step 2: Add students as external users with their eduID
You can only set the eduID through the Ans API, not in the Ans interface. Most institutions automate this from their SIS or IAM system, so a student is added to Ans as soon as they enroll.
- Create an API token under Personal settings > API tokens. Copy it right away: you cannot view it again later.
- Look up your school ID. The API token page shows it.
- Create an external user with
POST /api/v2/schools/{school_id}/external_users, and filledu_idwith the student's eduID. - Add the external user to the courses whose exams they take, either through the API or in Ans.
An example request body:
{
"first_name": "Sam",
"last_name": "de Vries",
"email": "sam.devries@example.com",
"role": "guest",
"edu_id": "8331e75b-7652-4367-a870-fd1da452c405",
"external_id": "S123456"
}| Field | What to enter |
|---|---|
edu_id |
The eduID identifier for your institution (urn:mace:eduid.nl:1.1), a UUID. Ans matches it at sign-in. Each eduID can belong to one account only. |
email |
The student's email address, usually the one linked to their eduID. It must be unique: no other Ans account can use it. |
external_id |
Optional. Your own reference, such as the student number in your SIS. Ans does not use it. |
To test your requests first, use the interactive API docs: click Authorize, paste your token, and try the External Users endpoints. You can also use a tool such as Postman.
Step 3: Students sign in with eduID
Share these steps with your students:
- Go to ans.app and click Log in with your school account.
- Search for your school and select it by the school name you entered in step 1.
- In the SURFconext screen, choose eduID and sign in.
Ans matches the eduID to the external user you created and opens their courses and exams. Students only see the courses they were added to at your institution.
Frequently asked questions
Can a student who studies at several institutions see data from the other institutions?
No. A student signed in with eduID only sees the courses and results they were added to at your institution, even if they also use Ans elsewhere.
What if a student also has a regular account at our institution?
The two accounts stay separate, each with its own results. Each account needs its own email address. Search for the student's name in Ans to find both accounts.
A student signs in with eduID but Ans does not recognize them. What now?
Check these in order:
- The
edu_idyou sent is the identifier for your institution. eduID gives each student a different identifier per institution, so an ID from another source will not match. - The student signs in with the same eduID that your SIS or IAM system registered.
- Your SURFconext connection for Ans has eduID enabled and releases the
urn:mace:eduid.nl:1.1attribute.
Still stuck? Contact our support team and include the student's email address and the time they tried to sign in.
Where can I read more about eduID identifiers? SURF explains them in eduID identifiers.
Comments
0 comments
Article is closed for comments.