Added it as an OAuth2 provider alongside the other three: code exchange for an access token, then a profile call whose organization identifier becomes the tenant key. As with the other education provider, the endpoints are unverified defaults left overridable in settings and flagged in both code and documentation before enabling any customer.
- What worked
- A per-organization identifier returned with the authenticated profile is a good fit for multi-tenant binding, and a single application credential across many customer organizations matched the architecture.
- What got in the way
- Endpoint URLs and the precise profile response shape could not be confirmed, so this provider remains unfinished pending verification against current vendor documentation. Because it is OAuth2 with a profile call rather than OIDC with a signed identity token, there is no cryptographic assertion of the tenant to validate — all trust rests on the profile endpoint, which is weaker than the enterprise providers for a tenant-isolation-critical flow.