SAML federation Education & research eduGAIN-ready

SURFconext integration development

Appfront connects your application as a Service Provider to SURFconext, SURF's federation hub for Dutch education and research. Students, teachers and researchers at affiliated institutions can log in to your app with their institutional account. We handle the full SAML implementation, attribute processing, testing on MujinaIdP and guidance through SURF onboarding to production release.

What is a SURFconext integration?

SURFconext is the Dutch federation hub for education and research, managed by SURF. It connects hundreds of Dutch education and research institutions with each other and with external applications. A student, lecturer or researcher signs in with their institutional account and gains access to connected external apps, from learning platforms to research tools and library environments.

For you as an application owner, this means one SAML integration with SURFconext, and all affiliated institutions can use your app. No separate integration per university or university of applied sciences: SURFconext handles the federation. You can also enable eduGAIN to be discoverable by academic institutions abroad.

Appfront builds in line with the official SURFconext developer documentation, the SURF standards framework and the OWASP ASVS security standard. We tailor attribute processing, session handling and test scenarios to your use case, so that onboarding with SURF runs smoothly and the integration remains easy to maintain.

SP

One integration, all institutions

A single SAML integration with SURFconext gives you access to hundreds of affiliated education and research institutions in the Netherlands. After onboarding, your app is automatically listed in the SURFconext catalogue and can be requested by any affiliated institution.

staff student org entitlement

Attribute-based authorisation

eduPerson attributes such as eduPersonAffiliation (student/staff/alumnus), schacHomeOrganization and eduPersonEntitlement control access rights in your app. We map them correctly in line with the SURFconext attribute release policy and GDPR principles.

Worldwide via eduGAIN

Through SURFconext you are automatically reachable by other academic federations worldwide via eduGAIN. Overseas researchers and students can sign in with their own institutional account, without you having to build a separate integration for each federation.

Our onboarding process for SURFconext

We work to a proven methodology that takes into account both the technical SAML implementation and the SURF onboarding process. From an initial analysis of your application and user roles through to production release and ongoing management, every step is aimed at an integration that remains maintainable in the long term.

1
Analysis & scope

We map out which eduPerson attributes your application needs, which user roles exist, and whether Strong Authentication or VOOT groups are relevant.

2
Architecture

We design the integration architecture, choose the right authentication and draw up an error-handling strategy.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What a SURFconext integration concretely delivers

Every SURFconext integration is set up specifically for your application and target audience. Below are the components we most often deliver for Service Providers joining the SURF federation.

Service Provider registration

Creating SAML SP metadata, configuring the entity ID and Assertion Consumer Service (ACS) URLs, and setting up certificates that can be rotated. We handle the application with SURF, work through the testing phase and guide you to production release.

Attribute processing

Correctly mapping eduPerson attributes to your internal user model: eduPersonAffiliation for roles (student, staff, alumnus), schacHomeOrganization for institution, and eduPersonEntitlement for entitlements. Including just-in-time provisioning on first login.

Strong Authentication

For apps with elevated risk, such as assessment systems, financial apps or research data containing privacy-sensitive information, we set up SURFconext Strong Authentication (SFO). Users then authenticate with MFA via their institutional IdP or SURFsecureID.

VOOT groups & Invite

Group management via VOOT or SURFconext Invite for multi-institutional collaborations. Ideal for project teams where researchers, lecturers or students from several institutions work together, and where guest users from outside SURFconext need to be invited.

Account linking and JIT provisioning

For apps with their own local user store, we make sure the SURFconext identity is correctly linked to existing or new user records. Just-in-time provisioning automatically creates an account at the first successful sign-in, including the right role based on eduPerson attributes.

Testing environment via MujinaIdP

Before your app goes live in the SURFconext production environment, we test thoroughly against MujinaIdP, SURF's test framework in which we can simulate different user roles, attributes and scenarios. This keeps the production release predictable and free of surprises.

Typical use cases in practice

We often see a SURFconext integration fall into a few recognisable scenarios. For each of these, we have a working setup, with particular attention to attribute release, session handling and onboarding.

EdTech vendors

SaaS products for education, from learning platforms and assessment tools to digital study environments and skills apps, reach hundreds of Dutch education institutions through a single integration with SURFconext. See also our custom software development services.

Research platforms

Platforms for research collaboration, data management and publication use SURFconext plus eduGAIN to give researchers worldwide access with their own institutional account. Attribute-based access control determines which datasets or tools are accessible per role or institution.

Library and content providers

Library systems, academic publishers and content providers connect their access systems to SURFconext so that students and researchers gain immediate access to journals, e-books, databases and repositories, without a separate sign-in for each service.

Inter-institutional collaboration

Consortia, joint degrees and sector-wide projects in which staff and students from several institutions work together. With VOOT groups and SURFconext Invite, you manage these multi-institutional groups centrally, with scoped access to shared apps and documentation.

Technology we use

We build SURFconext integrations using the standard SAML 2.0 and OIDC stacks that suit your application, along with testing on MujinaIdP. The precise choice depends on your framework and preferences, so that your own team can manage or further develop the integration.

SAML 2.0 OpenID Connect (OIDC via SURFconext) SimpleSAMLphp Shibboleth SP mod_auth_mellon Spring Security SAML Passport-SAML (Node.js) PySAML2 OmniAuth SAML (Ruby) eduPerson attribute schema schacHomeOrganization eduGAIN interfederation MujinaIdP testframework SURFsecureID / SFO VOOT for groups XML signing and encryption

Why choose Appfront for your SURFconext integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our wider services around API integrations, middleware, custom software development and web app development.

  • Experience with SAML Service Provider implementations and SURFconext onboarding
  • Understands eduPerson attributes and the SURF attribute release policy
  • Familiar with MujinaIdP test scenarios and production releases
  • Attention to attribute minimisation and GDPR in an education context
  • Structured error handling and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and proactive further development
  • A way of working aligned with your existing IT landscape

Security and privacy in SURFconext integrations

A federation integration involves the personal data of students, teachers and researchers. Appfront builds to the SURF standards framework and the OWASP ASVS. This includes attribute minimisation (only the eduPerson attributes that are genuinely needed), signed and, where necessary, encrypted SAML assertions, correct single logout (SLO) and careful certificate management with scheduled rotations.

SURFconext meets the SURF framework of standards and Dutch privacy legislation. We document which attributes are requested and why, so your record of processing activities is complete and you can demonstrably comply with the GDPR. For student records and other special categories, we make the appropriate assessments in consultation with your Data Protection Officer.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about SURFconext integrations

Answers to the questions we are asked most often about SURFconext Service Provider integrations.

A SURFconext integration connects your application as a Service Provider (SP) to SURFconext, SURF's federation hub for Dutch education and research. Students, teachers and researchers at connected institutions can log in to your app with their own institutional account. An integration typically covers SAML 2.0 metadata exchange, attribute handling (eduPersonAffiliation, schacHomeOrganization, eduPersonEntitlement), testing via MujinaIdP, and finally the production connection to SURF.

SURFconext is relevant when your application is used by Dutch education institutions or research organisations, such as EdTech platforms, research tools, library or journal environments, collaboration portals and policy apps. With a single SAML integration with SURFconext, you reach hundreds of institutions without setting up a separate federation for each one. For international institutions outside the Netherlands, eduGAIN serves as the broader federation.

The technical implementation of a SAML Service Provider is usually completed within a few weeks, including testing on MujinaIdP. On top of that comes the SURFconext onboarding process itself: registering as an SP, supplying metadata, completing the test phase and agreeing the production release with SURF. Allow a few extra weeks for that formal process, depending on SURF's turnaround and on the first institutions connecting.

Depending on your stack, we work with SAML libraries such as SimpleSAMLphp, Shibboleth SP, mod_auth_mellon, Spring Security SAML, Passport-SAML or PySAML2. We do testing via MujinaIdP, SURF's testing framework. We tailor eduPerson attribute mapping, just-in-time provisioning and session handling to your application. For OIDC integration with SURFconext, we use the standard OIDC libraries of your framework.

Costs are determined by the complexity of the data flows, the number of systems to connect, the required synchronisation frequency and the amount of custom business logic. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.

Yes. SURFconext complies with Dutch privacy legislation and the SURF framework of standards. Appfront builds to the OWASP ASVS and applies attribute minimisation: we only request the eduPerson attributes your app genuinely needs. SAML assertions are encrypted and signed where necessary, and single logout (SLO) is implemented correctly. For special categories of personal data (such as student records), we make the appropriate assessments in consultation with your Data Protection Officer.

Yes. Appfront regularly takes over existing SURFconext integrations, even when another party originally built them. We review the SAML configuration, attribute mapping, session handling and certificate management, document the current setup and propose improvements. From then on, we can handle changes, extensions and monitoring, including timely certificate rotation.

SURFconext is designed specifically for the Dutch education and research landscape. Typical use cases include EdTech vendors offering their app to Dutch universities, universities of applied sciences, MBO colleges or research institutes; research platforms and data tools that need to be widely accessible; library and journal access systems; collaboration portals for inter-institutional projects; and access to international services via the eduGAIN federation.

Ready to integrate your app with SURFconext?

Tell us which application you want to connect and which user roles and attributes are involved. We are happy to help with the SAML set-up, attribute release, testing on MujinaIdP and onboarding with SURF. A no-obligation first conversation will give you a clear picture of what is possible within half an hour.

Edit content