Add SSO login URLs to the Focused Browsing allowed list Follow
This article helps Hāpara administrators allow required login pages (SSO) so students can sign in successfully during Highlights Focus sessions.
Who this is for
Admins
Summary
If students are being blocked from a sign-in page during a Highlights Focus session, add the site’s SSO/login URLs to your domain’s allowed list (also called the Domain allow list in the updated Admin Console). This keeps those login/redirect pages accessible even when teachers run Focus sessions.
Steps to Follow
1) Collect the correct login URLs
Ask the teacher which site students are trying to access (for example: a digital textbook, assessment site, or state testing site).
Identify the login/redirect URL(s) students hit during sign-in (these are often different from the learning content URL).
Make sure each URL includes the full beginning of the address (including
https://orhttp://). You usually do not need the full ending path because the system matches URLs that start with the path you enter.
2) Add URLs in the updated Hāpara Admin Console (recommended path)
In the Hāpara Admin Console, go to Settings.
Select Highlights (Screens).
Find Domain allow list, then click Manage links.
Add one URL per line (include
https://orhttp://).Click Save.
3) If you’re using the legacy Admin Console (alternate path)
Go to Modules → Highlights in the Hāpara Admin Console.
Scroll to Focused Browsing Single Sign-On allowed list.
Add one URL per line (include
https://orhttp://), then Save.
4) Wait for changes to apply, then test
After saving, allow about 5 minutes for changes to reach student devices.
Have a teacher start a Focus session and confirm students can sign in without the login page being blocked.
Common allow list examples
Google SSO (common sign-in redirects)
Add these URLs if students need to sign in with Google during Focus sessions:
https://accounts.google.comhttp://accounts.google.comhttps://appengine.google.com
Clever SSO (common sign-in redirects)
If students sign in through Clever during Focus sessions, your school may need to allow one or more URLs used during the Clever sign-in and redirect process.
Common examples include:
https://clever.comhttp://clever.comhttps://s3.amazonaws.comhttp://s3.amazonaws.comhttps://filepicker.iohttp://filepicker.iohttps://filepicker.comhttp://filepicker.com
Important: Only add URLs that your school has confirmed are required for its Clever sign-in flow. Shared hosting domains such as
s3.amazonaws.comcan host content from many unrelated organizations. Allowing a shared hosting domain may make other content hosted on that domain accessible during a Focus session.
After adding the required URLs, test the complete Clever sign-in process using a student account.
If you need to allow a shared hosting domain
Some SSO services use shared cloud-hosting platforms during sign-in. These domains may also host unrelated websites and applications.
If your school needs a shared hosting domain for SSO:
- Confirm that the domain is required by testing the student sign-in process.
- Add only the URLs necessary for the login or redirect.
- Avoid adding additional parent domains unless they are required.
- Test the change with a student account during a Focus session.
- Use your Google Admin Console, web filter or network filtering solution to block specific unwanted hosts, buckets or paths when necessary.
Do not remove an existing SSO allow-list entry from a production environment until you have confirmed that student authentication continues to work without it.
Additional Tips
Only allow what is required: URLs added to the Domain allow list can become available to students during Focus sessions. Be especially careful with shared hosting domains such as AWS, cloud storage services and content delivery platforms because a single parent domain may contain content from many unrelated organizations. Confirm the required login URLs, use the narrowest URL possible and test with a student account before deploying changes broadly.
Collect + test ahead of time: Hāpara recommends collecting likely login-required sites from teachers and testing important sites (like state testing) before instructional time.
Teacher workaround (if a domain allow list update can’t happen immediately): Teachers can include known login URLs in their Focus session link list to reduce access errors.
Redirect-heavy sites: Some sites redirect through multiple pages during login; teachers may need students to sign in first (before starting Focus), or include both the content URL and login URL(s) in the same session when possible.