---
title: "Public Media Single Sign-On (SSO)"
canonical: "https://docs.pbs.org/space/PMSSO/29392997/Public%20Media%20Single%20Sign-On%20(SSO)"
format: markdown
---
> ⚠️ # **Onboarding for Public Media Single Sign-On is currently paused. We'll be sharing a project update soon.**

> Macro (toc)

## Overview

Public Media Single Sign-On (SSO) is a customer identity management platform developed by PBS for public media entities that allows organizations to add authentication to their website and apps. It eliminates the need for users to create separate accounts when moving between NPR, PBS, participating NPR & PBS stations, and third-party content providers (e.g., PRX).  For instance, a user can visit their local station website, the NPR One app, and the PBS Video app, all while using the same username and password. 

Simplifying logins across organizations allows users to be recognized over a variety of Public Media Touchpoints and reduces redundant technology spending for public media organizations who would otherwise need to invest in building and maintaining their own identity tools. It also provides audiences with a seamless login experience, especially if consuming content across various public media websites and apps.  

The image below illustrates the process an unknown user (i.e., a user who has never signed in to a public media site) goes through using SSO.

![sso-flow.jpg](media://60878414-8562-4486-9fd9-f82c164ce912)

## User Experience 

![sso-flow-redesign.mp4](media://00ea2a18-9f30-4652-802d-8d83714d4795)

Users who sign up for a PBS account through the PBS website can navigate between the PBS, NPR, and station sites without having to sign in again. Likewise, users who have an account through NPR.org can switch to PBS or station websites without signing in again. 

This section illustrates the process that enables this workflow. 

- From PBS.org, a user clicks** Sign In** (Figure 1).

> 📝 This example begins by signing in to [PBS.org](http://PBS.org), but this same flow applies to users who begin signing in on [NPR.org](http://NPR.org).

Figure 1

![sso-user-experience1.jpg](media://fdee6395-d800-4c50-80d5-4ce6a9983f11)

- The user is redirected to the Akamai login page.
- Akamai checks to see if the user has an existing SSO cookie.
  - Users who have an existing account should click **Sign in with Email** and log in with their existing credentials (Figure 2.1).
  - For users who are signing in for the first time, no SSO cookie is present and the user should click **Create an account** (Figure 2.2).

Figure 2

![sso-user-experience2.jpg](media://2cc0a4c1-592c-4e45-aaaf-b99c6884a07b)

- Once the user has logged in, Akamai sets an SSO cookie and redirects the user to PBS.org, where the user's login is displayed (Figure 3.1).
- The user opens a new tab or window and navigates to NPR.org (Figure 3.2).

Figure 3

![sso-user-experience3.jpg](media://182a5e31-14a4-4dee-8c1a-42a7b7a1cef5)

- The user clicks **Sign In **on the NPR site** **(Figure 4).

Figure 4

![sso-user-experience4.jpg](media://a908240a-02d6-40a0-ad8f-5687a0128fde)

- NPR redirects the user to the Akamai login page.
- Akamai finds the SSO cookie and asks if the user wants to sign in using the existing account by accepting the *NPR Privacy Policy/Terms of Use*.
- The user clicks **Accept and Continue** (Figure 5).

Figure 5

![sso-user-experience5.jpg](media://af54a822-ccc6-455b-866b-bf383e8d366b)


- Once the user accepts the terms, a success message displays and the user is redirected to NPR.org.

Figure 6

![sso-user-experience6.jpg](media://496698ef-c298-4310-97e8-ebb34da741e8)

## Features 

The following are features of SSO:

| **Feature** | **Description** |
| --- | --- |
| **Registration** | Users can create a new account using the registration form. |
| **Authentication** | Registration and login via password. |
| **Single Sign-On** | Users who log on to one application can be recognized across other applications. |
| **Password Reset and Security** | User can reset their password in a self-service workflow. Password encryption, password validation rules, and secure password reset are supported. |
| **Profile** | Users can view and edit their user profile. |
| **Social Identity ** | Registration and login via Apple, Facebook, and Google. |
| **Merge Accounts** | Merge accounts such as Traditional, Apple or Facebook with an existing profile. |
| **Branded** | Customize the look and feel of the login, registration, and profile screens and email templates. |
| **Account Verification** | Require verification for new traditional accounts. |
| **Subject Access Rights** | Users can request their data or account deletion. |
| **Privacy and Terms Acceptance ** | Users must accept legal terms upon registration, on initial login to organization, or any time legal terms are updated. |
| **Web Browser Support** | Latest versions of Chrome, Edge, Firefox, Safari. |
| **Customer Care Portal** | Portal for customer care agents to service user profiles. |

## Reference materials

[Data Protection Addendum](https://docs.pbs.org/space/PMSSO/4111920/Data+Protection+Addendum)

[Service Recipient Terms of Use](https://docs.pbs.org/space/PMSSO/4111927/Service+Recipient+Terms+of+Use)

## General FAQs 

<details>
<summary>What is Public Media Single Sign-On (SSO)?</summary>

Public Media Single Sign-On (SSO) is an identity management solution designed to streamline the user login experience across various public media platforms, including station websites and apps. This service offers a unified login system that replaces disparate, often “homegrown” tools to identify and register users on digital platforms (e.g., NPR, PBS Roku app, [myGBH.org](http://myGBH.org) ). Users can easily navigate different public media services with just one set of login credentials, eliminating the need for multiple accounts.

This solution includes user registration on station websites and apps, which is a foundational element for personalization and critical for your marketing and audience development efforts to reach and engage both new and existing users and transform casual users into local members and donors. Public Media SSO will enable stations to start to build a strong one-to-one connection with their local audiences.
</details>

<details>
<summary>What are the key benefits of Public Media SSO for the system and for stations?</summary>

Enhanced User Experience and Streamlined Access: Public Media SSO is a convenient way for users to access various public media products and services by logging in once. It eliminates the need to remember multiple usernames and passwords, encouraging more frequent and engaged use of our services and access to benefits, such as PBS Passport. 

Opportunities for Enhancing Station Lead Generation Efforts and Conversion: By integrating Public Media SSO and user registration on your website and apps, a station can start identifying its users. This is a foundational element for more personalized and targeted audience engagement efforts with both new and existing users. Offering a logged in state for a station’s digital platforms, when paired with a station’s member management systems Public Media SSO will help stations start to build user profiles, develop one to one relationships with your digital users, and enable better understanding of their preferences and behaviors. 

Reduced Costs Through Shared System-Wide Digital Infrastructure: This system-wide technology reduces' participating stations’ costs associated with maintaining separate login systems.
</details>

<details>
<summary>Is there a cost for using Public Media SSO?</summary>

There is no cost for adopting and using Public Media SSO. The cost has been funded initially through a 3-year grant to PBS from CPB that covers the licensing, development and support fees for any interested public media entity who wants to use the Public Media SSO. Stations may incur specific costs related to technical implementation of Public Media SSO on their station websites.
</details>

<details>
<summary>Will we be able to add Public Media SSO to our Bento and Grove CMS/websites?</summary>

Yes – both PBS and NPR have successfully integrated SSO service and functionality into these two CMS platforms. The service must still be enabled in order to go live (see 'When will I be able to enable Public Media SSO).
</details>

<details>
<summary>When will I be able to integrate Public Media SSO into my station website?</summary>

PBS will be grouping interested stations/organizations into cohorts over the Spring and Summer of 2024. Once PBS receives your station’s Interest Form, linked above, your station will be grouped into a cohort based on similarities with other stations- such as similar CMS, Bento, or Grove sites, license type, etc. This is for ease of onboarding and training. 

Questions about Public Media SSO onboarding and cohorts can be directed to the SPI PBS Station Products and Innovation team (SPI) at [spi@pbs.org](mailto:spi@pbs.org).
</details>

<details>
<summary>We have a mobile app hosted by a vendor. Can Public Media SSO be implemented with station mobile, OTT apps or other websites?</summary>

Yes – stations’ local apps will be able to take advantage of the Public Media SSO, enabling their users to use a single set of login credentials across multiple mobile and website destinations.
</details>

<details>
<summary>Will Public Media SSO support any existing products or services requiring registration offered by PBS and NPR? How does SSO affect PBS Passport?</summary>

The SSO service will make it easier for users to use the same sign-in across NPR and PBS products, including mobile apps, websites, and services like PBS Passport. 

There will be no changes to PBS or NPR Products, and the launch does not affect a user's Passport access.
</details>

<details>
<summary>Can I use Public Media Single Sign-On for enterprise applications such as my internal CRM?</summary>

SSO is intended for audience-facing authentication, not for enterprise single sign-on purposes.
</details>

<details>
<summary>Will user data be shared across NPR, PBS, and stations?</summary>

At the national level, NPR and PBS will only have access to data granted by both the user and the organization from which the information is sourced. When the user chooses to authenticate with any organization, their authentication data will be shared with the appropriate organization. SSO only provides a single authentication layer.  

Public Media SSO participants are responsible for maintaining the security of user data and complying with any applicable privacy laws within their internal systems as outlined in the PBS Data Protection Addendum and Terms of Service.
</details>

<details>
<summary>What technical specifications are required for a station/organization to integrate Public Media SSO?</summary>

[Please refer to PBS documentation for technical specifications, including our development guide to integrate SSO.](https://docs.pbs.org/space/PMSSO/28901394/Developer+Guide)
</details>

<details>
<summary>I have more questions; how can I contact NPR and PBS Support teams?</summary>

- Questions about Public Media SSO onboarding from any public media station/organization can be directed to the PBS SPI team at [spi@pbs.org](mailto:spi@pbs.org).
- Questions about PBS products can be directed to the PBS Support team at [http://digitalsupport.pbs.org](http://digitalsupport.pbs.org/).
- Questions about NPR products can be directed to the NPR team at [https://studio.npr.org/s/support-home](https://studio.npr.org/s/support-home).
</details>