Alumni · 10 min

Google and LinkedIn SSO: what one-tap sign-in changes for an alumni network

An alumni platform gets chosen on its directory, its events and its mentoring. It then gets judged on how many members actually sign in. In between sits a screen nobody discusses at the steering committee: the one asking a graduate to pick a password before they have any idea what they get in return. Here is what signing in with Google or LinkedIn really moves, what it does not do, and the check to run before you mention it to your members.

September 1, 2026 ~10 min read By Thibault Sabathier
TL;DR

The first obstacle of an alumni network is almost never the feature set, it is signing up. Asking a graduate for a password before they have seen anything of the platform is asking for effort whose payoff is deferred, and deferral turns into abandonment. Signing in through an identity provider removes that effort: the official documentation for Sign in with Google describes a sign-up pre-filled from the profile and a one-tap sign-in for anyone already signed in to their Google Account, while LinkedIn relies on the Authorization Code Flow documented by Microsoft. Three cautions come with the gain: SSO authenticates but certifies no degree, it sits alongside the password rather than replacing it, and the google_sso and linkedin_sso modules are included only in the Premium and Business Club plans.

The point where an alumni network loses its members is not the one you would expect

The path is always the same. An invitation goes out by email, the recipient clicks, and lands on a form. First name, last name, address, password, confirm password. At that precise moment they have seen nothing of the platform, they have no reason yet to want it, and they are being asked to invent and memorise one more secret. They tell themselves they will do it tonight. Tonight, the email is buried under twenty others.

What happens there is not an ergonomics problem but a sequencing one. The effort is demanded before the benefit has been shown, whereas the whole rest of the product is designed the other way round. The sign-up form is the only screen of an alumni platform that asks for something while giving nothing, and it is the one everybody has to pass through.

The password is then paid for a second time, in resets. The alumni manager becomes a part-time help desk on a subject that benefits nobody. And a third time, invisibly: the member who cannot sign in again six months later does not ask for help, they close the tab. They show up in no support statistic, only in the slow erosion of the active base, the one people try to reverse far too late with campaigns to wake a dormant network.

Sign in with Google: what the official documentation says

Start with the name, because it is routinely mangled. The service is called "Sign in with Google". People often write "Google SSO" as though that were a product name: it is not. The precision matters the day you go looking for the documentation, the day you draft a privacy notice, or simply the day you want to be credible in front of an IT department.

The official documentation describes three entry points, worth quoting literally: "Sign up, to optionally create a new account auto-filled from a Google Account profile", "Sign in, using an account chooser to select from multiple accounts", and "Sign in with one tap, if you've already signed in to your Google Account". Translated into alumni-manager language, those three lines say this: account creation fills itself in from the profile, signing in offers a choice among the accounts available on the device, and a member already signed in to their Google Account gets in with a single gesture.

The same page describes the overall mechanism: the user can "sign into a Google Account, provide their consent, and securely share their profile information with your platform". The order of those three elements is the entire reasoning. Authentication happens at Google, consent is requested from the user, and the platform receives profile information. What your platform never sees at any point is a password: there is none left to protect, none to reset, none to lose.

LinkedIn: a standard authorization flow, to re-check when you connect it

On the LinkedIn side, sign-in relies on the Authorization Code Flow, officially documented by Microsoft. It is a standard flow, the one found at most identity providers, and naming it is enough to situate the subject with a vendor or an IT team.

We deliberately stop there. What a flow transmits exactly, which authorization scopes are available and what conditions apply to them all evolve with the provider's programmes, and an article that spells them out goes stale without warning its reader. The prudent rule is therefore simple: open the official documentation at the moment you connect it, rather than trusting what you remembered from last year.

That caution has a practical rather than theoretical consequence. Whatever a platform receives from an identity provider has to appear in the information you give your members, and that list is drafted from the documentation as it stands on the day you connect. It is one more line in the documentary obligations we detail in our GDPR checklist for an alumni directory, and one of the few that takes ten minutes if you handle it at the right moment.

SSO authenticates, it certifies no degree

Here is the most expensive confusion on the subject, and it slips into meetings in a reassuring form: "with LinkedIn sign-in, we will know who they are". No. A Google account or a LinkedIn profile proves the person on the other side controls that account. It says nothing about their graduating class, nothing about their school, nothing about whether their membership fee is paid up.

Membership verification therefore stays where it already was: the named invitation sent from the database, the graduation list supplied by the registrar, or approval by an administrator. SSO does not replace that filter, it replaces the password. Opening Google sign-in without keeping an entry control does not produce an alumni network, it produces a directory open to anyone with an email address.

The order to remember fits in one sentence: first decide who is allowed in, then decide how that person signs in. The two questions are independent, and treating them separately avoids most of the bad surprises. Once the distinction is made, SSO becomes what it actually is, an improvement in convenience of access, and not an admissions policy in disguise.

The school address expires, the personal account remains

The switch from student to alumnus concentrates almost all the risk of losing contact. The institutional address is deactivated a few months after graduation, and with it go the sign-in identifier, the follow-up channel and often the only address the school held. That is the breaking point we describe in our article on the automatic switch from student to alumni status.

A personal Google account or a LinkedIn profile, by contrast, survives graduation, a house move and three changes of employer. Anchoring sign-in to an identity the graduate keeps, rather than to an address the institution takes away, does not remove the problem but moves it somewhere manageable. This is design reasoning, not measurement: we put forward no rate here, and we would treat the ones in circulation with caution.

None of which removes the need to collect a personal address before they leave, which remains the best insurance and the first habit to establish with outgoing classes, as we set out on engaging young graduates. SSO is a second line, useful precisely on the day the first one was forgotten.

Signing in with LinkedIn is not running your network on LinkedIn

The two subjects carry the same brand name and have almost nothing in common. Signing in with LinkedIn is a way into your platform. Running your community inside a LinkedIn group is a choice of venue, which amounts to handing a third party the directory, the relationship with members and the data that goes with it. We devoted a full comparison to that second subject, between LinkedIn and an alumni platform.

SSO can in fact be read as the pragmatic answer to that dilemma. You take from LinkedIn what it does better than anyone, a professional identity kept up to date by the person themselves, without handing over the directory, the association's memory, or the ability to reach your members. The dependency is then confined to the front door, and it stays reversible as long as another door exists.

When the ordinary password remains the right choice

It would be dishonest to present SSO as the end of the password. Some members of an alumni network use neither a Google account nor a LinkedIn profile, and it is not a matter of generation: sometimes it is a deliberate choice, sometimes a professional context, sometimes a country where other services dominate. Shutting the door on them to simplify our own side would be a poor trade.

Some organisations, next, tightly govern the use of external identity providers, and a public institution may prefer its own directory for reasons that are not settled at the level of an alumni project. The subject then goes up to an IT department, and the right answer is to offer the choice rather than impose a channel.

Finally there is the dependency itself. A member who loses access to their Google account loses their way in, and they lose it on a Sunday evening, before a general meeting. Hence the rule that sums up this section: SSO is added, it does not replace. Keeping a password route costs little, and it is what turns a dependency into a convenience.

Connecting SSO to an alumni network, in six steps

  1. Check the plan before promising anything. The google_sso and linkedin_sso modules are included only in the Premium and Business Club plans. The check takes a minute and saves an announcement you would have to withdraw.
  2. Add SSO without removing the password. The goal is to take away an obstacle at the entrance, not to create a new one for those who do not hold the accounts concerned.
  3. Decide how existing accounts are reconciled. A member already registered who arrives through Google must find their record, not create a second one. That rule is settled before you open, never after the first duplicate.
  4. Keep the membership filter. Named invitation, graduation list or approval by an administrator: SSO does not say who is allowed in, it says only how they get in.
  5. Write down what is transmitted. Draft the list of information received from the identity provider from its official documentation, on the day you connect it, and fold it into what you tell your members.
  6. Test from an account that is not yours. On a phone, with an ordinary account, without already being signed in to the admin area. It is the only test that reveals what a member actually experiences.

Which plans include it, and why to check before you talk about it

The google_sso and linkedin_sso modules are present only in the Premium and Business Club plans. They are included in neither Starter nor Pro. This is not a pricing footnote but a scheduling constraint: announcing one-tap sign-in in a membership campaign while the network is on Pro forces you to walk it back at the worst possible moment, the one where you were asking members for an effort.

So the check comes before the communication, not the other way round. It holds for SSO as for any announced feature: the question is not whether the platform can do it, but whether your plan includes it. For the rest, signing in with Google or LinkedIn spares you none of the groundwork described here: it simply removes an obstacle placed at the worst point of the journey, just before the member has seen any reason to stay. The full picture of what the platform covers is on the Terrilink for Alumni page.

In short

Does SSO remove passwords for my members?

It should not remove them, it should sit alongside them. SSO takes away the obligation to create a password at sign-up, which is where the friction is. Keeping a password route remains necessary for members who have neither a Google account nor a LinkedIn profile, and for anyone who loses access to theirs.

Is signing in with LinkedIn the same as running your network on LinkedIn?

No, and the confusion is common. LinkedIn SSO is a way into your own platform. Running your community inside a LinkedIn group is a choice of venue, which hands a third party the directory, the relationship and the data. You can use the first without doing the second.

Does SSO prove the person actually graduated from the school?

No. A Google account or a LinkedIn profile proves the person controls that account, nothing more. Membership verification stays with the named invitation, the graduation list or approval by an administrator. SSO replaces the password, not the entry filter.

Is SSO available in every Terrilink plan?

No. The google_sso and linkedin_sso modules are included only in the Premium and Business Club plans. They are available in neither Starter nor Pro, which is worth checking before announcing one-tap sign-in in a membership campaign.

Method and sources. The wording relating to Google comes from the official Sign in with Google documentation, consulted on August 31, 2026, from which the exact service name and the three described entry points are taken. The flow used by LinkedIn is named after the official Microsoft documentation of the Authorization Code Flow, consulted on the same date; we assert nothing more precise than the name of the flow, and we recommend opening that page at the moment you connect it. The availability of the google_sso and linkedin_sso modules in the Premium and Business Club plans only comes from Terrilink product documentation. The rest of the article is organisational reasoning drawn from our practice and not a measurement: we deliberately put forward no activation, conversion or sign-up rate, having measured none ourselves. This article is neither legal advice nor technical integration documentation.

A sign-up that asks for no effort before giving anything

Directory, events and messaging in one place, with a way in through a Google or LinkedIn account and a membership control that stays yours. Terrilink for Alumni, no technical skills required.