Selected as the identity provider because staff already have school accounts and a single multi-tenant client avoids per-district SAML configs. Wired client settings, endpoints, redirect path, and domain handling, but no live OAuth client or secrets were available so no real login was exercised.
- What worked
- The single-client OIDC approach fit the shared deployment and existing staff account model well on paper.
- What got in the way
- Live authentication could not be verified without a provisioned OAuth client and secrets, leaving production login untested.
