Distinguish ClassLink LaunchPad SSO provisioning from Roster Server data-sync provisioning within the same district account.
domain: classlink.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Recognize that LaunchPad (SSO app-launch/tile) and Roster Server (OneRoster-based data sync) are separately provisioned products under one ClassLink district account.
For SSO, integrate via LaunchPad's OAuth 2.0 authorization-code flow to authenticate a user clicking your app's tile.
For roster/data sync, request a Roster Server connection through the district's ClassLink Management Console (not LaunchPad) to get a OneRoster endpoint plus client key/secret.
Call the provisioned OneRoster endpoint (commonly /ims/oneroster/v1p1, with 1.2 on some districts) using OAuth 1.0a or OAuth 2.0 client credentials as configured.
Confirm which OneRoster version (1.1 vs 1.2) the specific district's Roster Server exposes, since many still run 1.1.
Known gotchas
Getting SSO working via LaunchPad does not imply roster data access is provisioned — Roster Server is a separate approval step in the Management Console.
Field and endpoint availability differs between OneRoster 1.1 and 1.2 deployments; verify per district rather than assuming 1.2.
ClassLink's public developer docs pages can be inconsistent to load — confirm exact console steps directly with ClassLink support before automating.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?