Enterprise SSO Authentication for AI Learning Platform on GCP
Client
Confidential
Sector
Enterprise Learning & Development / EdTech
Country
Canada
The client operates an enterprise AI-powered learning platform built on GCP, designed to scale across corporate environments with a unified web and mobile experience. Its cloud-native architecture is based on GraphQL, Cloud Run, and Firebase Authentication.
In this context, the client aimed to evolve its authentication system to enable enterprise Single Sign-On (SSO).
Initial situation:
- Authentication based on Firebase (email, password, and phone)
- No support for corporate identities
- Solid architecture, but without SSO
Business need:
- Enable access using corporate accounts
- Google Workspace
- Microsoft Entra ID
- Meet enterprise client requirements
Challenge for Arkkosoft:
- Extend the existing authentication system
- Without modifying the core architecture
- Without impacting operations or user experience
Solution and Implementation Approach
Arkkosoft designed and implemented an extension of the existing authentication system to incorporate federated identity login, using widely adopted enterprise standards and without redesigning the client’s architecture.
Federated authentication implementation
- Integration of SAML (Security Assertion Markup Language) to enable delegated authentication with corporate identity providers
- Implementation of OpenID Connect (OIDC) over OAuth 2.0
- Enablement of login with corporate accounts from:
- Google Workspace
- Microsoft Entra ID
- Elimination of the need to manage additional credentials within the platform
Implementation approach
- Extension of the existing architecture, with no structural changes
- Reuse of existing Firebase Authentication flows
- Integration of new identity providers as an additional layer
- Alignment with the architecture based on Cloud Run and GraphQL
- Use of the existing pipeline for controlled deployments (feature branches and production)
Implementation outcome
- Fast implementation by leveraging existing components
- Secure integration without introducing disruptive changes
- Controlled deployment aligned with the client’s processes
Frictionless experience for end users
Technologies Used by Arkkosoft
Authentication & Identity
- Firebase Authentication
- SAML
- OpenID Connect (OIDC)
- Google Workspace
- Microsoft Entra ID
Backend Integration
- js
- Express
- GraphQL
Cloud & DevOps
- Google Cloud Run
- Cloud Build
Frontend (Web)
- js
- React
Mobile
- React Native
- Expo
- Firebase Auth SDK
Impact and Benefits
Arkkosoft’s intervention generated a direct impact on business outcomes and user experience:
Enablement of modern enterprise authentication (SSO)
Enablement of modern enterprise authentication (SSO)
Exclusive access through authorized corporate accounts
Elimination of uncontrolled personal credential usage
Improved login experience (faster and frictionless)
As a result of the implementation, the client achieved:

