Overview
The Thought Industries (TI) integration connects your TI learning environment with Certiverse, so learners can take certification exams without leaving their course experience. The integration uses JWT-based Single Sign-On (SSO) and TI External Activities to securely pass learner and course information between the two platforms.
When a learner opens the External Activity in TI, they're signed in to Certiverse automatically, where they can schedule and take their exam. Once the exam is complete, the result is posted back to the same TI assignment, keeping learner records up to date without any manual steps.
The integration consists of three primary components:
- Single sign-on (SSO). The External Activity directs the learner to a Certiverse URL that includes a signed token from TI. Certiverse uses this token to create or update the candidate record.
- Eligibility. During sign-in, Certiverse verifies the learner’s course enrollment through the TI API and grants exam eligibility for the configured number of days.
- Result post-back. After the exam is scored, Certiverse updates the TI assignment as completed for a passing result or incomplete for a failing result, and sends the learner’s score.
Single sign-on from Thought Industries
The External Activity directs the learner to your organization’s Certiverse SSO page and includes the exam code, eligibility duration, and TI-signed token as query-string parameters.
URL format
https://{certiverse-login-domain}/#/sso/{organizationCode}/connections/{connectionCode}?exam_id={examCode}&days={days}&jwt={token}
| Parameter | Where | Required | Meaning |
| organizationCode | Path | Yes | Your organization's store code in Certiverse. Certiverse provides it. |
| connectionCode | Path | Yes | The code of the TI SSO connection Certiverse sets up for you. Certiverse provides it. |
| exam_id | Query | Yes | The Store Exam Code of the exam the learner is eligible for. Not case-sensitive. |
| days | Query | Yes | How many days the learner stays eligible, counted from their TI course enrollment date (not from sign-in). Use a positive whole number. |
| jwt | Query | Yes | The signed token from TI (see below). |
If any required parameter is missing or invalid, sign-in fails and the learner sees an error.
Examples
https://{certiverse-login-domain}/#/sso/acme/connections/acme-ti?exam_id=CERT-101&days=90&jwt=eyJhbGciOi...
https://{certiverse-login-domain}/#/sso/acme/connections/acme-ti?exam_id=cert-201&days=365&jwt=eyJhbGciOi...
The first grants 90 days to book CERT-101 after enrollment; the second grants a year for CERT-201.
Token fields
The jwt must be signed with HS256 using the shared signing secret. Expiry, issuer and audience are not checked. Certiverse reads these fields:
{
"email": "jane@acme.com",
"firstName": "Jane",
"lastName": "Doe",
"courseId": "course-uuid",
"returnTo": "https://acme.thoughtindustries.com/...?jwt=<activity token>"
}The activity token inside returnTo supplies:
{ "assignmentId": "assignment-uuid", "learnerId": "learner-uuid" }{ "assignmentId": "assignment-uuid", "learnerId": "learner-uuid" }| Field | Required | Used for |
| email, firstName, lastName | Yes | Creating or updating the Certiverse candidate. email also finds the learner in TI. |
| learnerId | Yes | The learner's SSO identity in Certiverse. |
| assignmentId | Yes | The TI assignment that receives the result. |
| courseId | Yes | Looking up the learner's enrollment in that course. |
| returnTo | Yes | Carries the activity token. |
After sign-in
- If the learner has already booked the exam, they are directed to their Certiverse dashboard.
- If the learner is eligible, they are directed to the exam checkout page.
- If neither condition applies, they are directed to your organization’s exam store.
API calls Certiverse makes to ThoughtIndustries
Certiverse calls four TI API v2 endpoints, so the API key needs read and write access. TI never calls Certiverse directly.
Every call goes to {your TI domain}/incoming/v2/... with the header Authorization: Bearer {API key}.
| Method | Endpoint | When | Access |
| GET | /content?types[]=learningPaths | When an admin validates the API key in Certiverse | Read |
| GET | /users/{email or learner id} | At sign-in and at checkout | Read |
| GET | /events/courseAction?userId={id}¬ifiableId={courseId} | At sign-in | Read |
| POST | /assignmentExternalActivity | After the exam is scored | Write |
GET /content
This call confirms that the API key is valid; Certiverse does not use the response data.
GET /users/{email or learner id}
No additional data is sent beyond the path. Certiverse reads two fields from the response and uses learnerUserId when available; otherwise, it uses id:
{ "id": "abc-123", "learnerUserId": "u-789" }GET /events/courseAction
Certiverse uses the most recent enrollment event to start the eligibility window. If no enrollment event is found, sign-in fails.
{
"pageInfo": { "hasMore": false },
"events": [ { "type": "enrollment", "timestamp": "2026-09-01T14:00:00Z" } ]
}POST /assignmentExternalActivity
{
"learnerId": "u-789",
"assignmentId": "assignment-uuid",
"status": "completed",
"grade": 85
}- status is completed if the candidate passed and incomplete if they failed.
- grade is the percentage score with decimals dropped, left out if the exam has no score.
- learnerId is the TI id found at sign-in; assignmentId comes from the activity token.
Configuration in Certiverse
Certiverse requires four setup items: your Organization provides the API key and signing secret, and the Certiverse Integrations team configures the SSO connection.
| Step | Who | What |
| 1. Thought Industries connector | Your Certiverse Organization admin | In Admin → Organization → Connectors, add an eligibility connector for Thought Industries with your API key and TI domain (for example https://acme.thoughtindustries.com). Click Validate to test the key. The key is stored encrypted. |
| 2. SSO connection | Certiverse Integration team | Creates the Thought Industries SSO connection using the signing secret you provide, then shares the connection code for the URL. The secret is stored encrypted. |
| 3. Enable the SSO connection | Your Certiverse Organization admin | In Admin → Organization → User Authentication, enable the new SSO connection for your organization. |
| 4. Exam eligibility | Your Certiverse Organization admin | For each store exam, add an eligibility configuration, select Thought Industries as the provider, and use the connector created in Step 1. No additional fields are required. |
The API key and signing secret are separate values. The API key authorizes Certiverse API calls to TI, while the signing secret verifies tokens sent from TI to Certiverse.
Configuration in Thought Industries and linking content
A TI course is linked to a Certiverse exam only by the URL in its External Activity. Nothing in Certiverse maps TI courses or assignments; their ids arrive in the token at sign-in.
In Thought Industries you need:
- An API key with read and write access to the endpoints above, shared with your Certiverse Organization admin.
- A signing secret for the SSO token, shared with Certiverse Integrations team, called “Vendor API Key” in TI.
- In each course, an External Activity must contain your Organization’s Certiverse SSO URL, with that exam's exam_id and the days you want.
To link a course to an exam:
- Ensure the exam in Certiverse has Thought Industries eligibility configured.
- Copy the exam's Store Exam Code into exam_id.
- Put the full URL in the course's External Activity, along with the jwt parameter.
The learner must be enrolled in the TI course before launching the External Activity because eligibility is based on the enrollment date.
Thought Industries manages the screens for creating External Activities and configuring the signing secret; refer to the TI External Activity documentation for those steps and helpful screenshots.
End to End Completion Flow
Certiverse posts the result to the same TI learner and assignment used at sign-in by storing both values on the learner’s eligibility record and retrieving them after scoring.
- Sign-in: Certiverse finds the learner in TI by the email in the signed token and stores their TI learner id and the assignmentId on a new eligibility record.
- Checkout: The learner can only book with an unused eligibility record that matches their TI learner id and the exam.
- Learner launches exam: The learner launches the exam from their Certiverse dashboard or exam appointment after booking is complete.
- Scoring: Once the exam is scored, Certiverse posts the result for that record's learner and assignment. Both passes (completed) and fails (incomplete) are sent.
Certiverse creates one eligibility record per learner per course. If the learner launches again from the same course, Certiverse reuses the existing record and original assignment.
Course or Learning Path -
Certiverse updates only the assignment for the External Activity and does not reference the learning path. Completion rollup to the course or any parent learning path follows ThoughtIndustries’ completion rules.
Updated
Comments
0 comments
Please sign in to leave a comment.