LMS SSO: SAML vs OpenID Connect for Your Learning Platform
A practical guide to single sign-on for your LMS: choosing SAML or OpenID Connect, provisioning users with JIT or SCIM, mapping roles and cohorts, an…
LMS engineering team - taking new projects
Senior engineers with 10+ years of building learning platforms. Whether you are starting from scratch, extending an in-house LMS or rescuing one whose original team has gone, we bring the standards, security and architecture that learning products need.
Get a free custom LMS estimate
Takes 2 minutes. A senior engineer replies - not a salesperson.
Why teams hire us for custom LMS work
Custom learning platforms usually reach us at one of three moments: a new build, a growth spurt, or a team that has moved on.
We design and build a platform around your workflows, with the learning standards and integrations built in rather than bolted on.
We audit the codebase, document the architecture, fix the riskiest problems first and take over development with a clean hand-over plan.
Standards-compliant players, a learning record store or LRS integration, and LTI 1.3 tool or platform support.
SAML and OIDC sign-in, SCIM provisioning, audit logs, role-based access and the documentation security questionnaires ask for.
Multi-tenant architecture with per-client branding, seat limits, data separation and reporting.
Automated tests, CI/CD, staging environments and observability, so you can ship weekly with confidence.
What our custom LMS developers do
Discovery, architecture and delivery of a platform designed around your model.
Architecture review, security audit and a documented hand-over from previous teams.
SCORM 1.2 and 2004, xAPI with an LRS, cmi5 and LTI 1.3.
SAML, OIDC, SCIM and role mapping for enterprise customers.
Per-client branding, seats, data separation and admin delegation.
Public APIs, webhooks, HRIS, CRM and payment integrations.
Dashboards, exports and data pipelines built on clean learning data.
Responsive web apps, PWAs and native apps on top of your platform API.
Threat modelling, OWASP reviews, load testing and tuning.
Code-level expertise
Learning platforms live or die on standards and data quality. We build on SCORM, xAPI, cmi5 and LTI 1.3 so content and tools work everywhere, and we treat learner data with the care security reviews expect.
This example sends a "completed" xAPI statement to a learning record store.
<?php
declare(strict_types=1);
namespace App\Learning;
final class XapiClient
{
public function __construct(private string $lrsUrl, private string $key, private string $secret) {}
public function completed(string $email, string $name, string $activityId, string $title, float $score): void
{
$statement = [
'id' => self::uuid(), // stable id: safe to retry
'actor' => ['mbox' => 'mailto:' . $email, 'name' => $name],
'verb' => ['id' => 'http://adlnet.gov/expapi/verbs/completed', 'display' => ['en-US' => 'completed']],
'object' => ['id' => $activityId, 'definition' => ['name' => ['en-US' => $title]]],
'result' => ['completion' => true, 'score' => ['scaled' => max(0, min(1, $score))]],
'timestamp' => gmdate('c'),
];
$ch = curl_init(rtrim($this->lrsUrl, '/') . '/statements');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 10,
CURLOPT_USERPWD => $this->key . ':' . $this->secret,
CURLOPT_HTTPHEADER => ['Content-Type: application/json', 'X-Experience-API-Version: 1.0.3'],
CURLOPT_POSTFIELDS => json_encode($statement, JSON_THROW_ON_ERROR),
]);
curl_exec($ch);
if (curl_getinfo($ch, CURLINFO_HTTP_CODE) >= 300) {
throw new \RuntimeException('LRS rejected the statement'); // the job queue retries
}
}
private static function uuid(): string
{
$b = random_bytes(16);
$b[6] = chr((ord($b[6]) & 0x0f) | 0x40);
$b[8] = chr((ord($b[8]) & 0x3f) | 0x80);
return vsprintf('%s%s-%s-%s-%s-%s%s%s', str_split(bin2hex($b), 4));
}
}
Skills
Engagement models
Pick the model that fits today and switch when your needs change. Every model includes a senior engineer, code review and a staging site.
Bug fixes, small changes, audits and urgent issues.
from $45/hour
Steady roadmap work and ongoing maintenance.
from 2500/month
Large roadmaps, platform teams and agencies.
from 4500/month
Well-defined features, migrations and new builds.
from 3000 minimum
Every engagement starts with a free technical call and an NDA. Prices exclude applicable taxes.
How it works
2 minutes
New build or existing system, your users and what is not working. The short form takes two minutes.
45 minutes
A senior engineer walks through your goals, constraints and, for existing systems, the architecture and codebase.
2-5 business days
You get a written plan: a fixed-price discovery or build phase, or a dedicated team with named engineers and monthly pricing. NDA signed first.
Fortnightly demos
Two-week iterations with demos, automated tests and staging environments. You see working software from the first cycle.
Compare
| Criterion | All-in-One LMS | Freelance marketplace | In-house hire |
|---|---|---|---|
| Engineers who work only on learning platforms | Yes | Partial | Partial |
| One team for WordPress LMS, Moodle, Open edX, Canvas and custom LMS | Yes | No | No |
| Cover when your developer is ill or on leave | Yes | No | Partial |
| Code review and QA before every release | Yes | Varies | Partial |
| NDA and IP assignment in the contract | Yes | Varies | Yes |
| No recruitment, payroll or notice periods | Yes | Yes | No |
| Scale hours up or down month to month | Yes | Partial | No |
| One accountable point of contact | Yes | No | Yes |
A general comparison of how each model usually works. Individual freelancers and in-house teams vary.
A custom LMS makes sense when learning is part of your product, when your workflows do not fit any platform, or when ownership of data and roadmap matters more than time to launch. It rarely makes sense just to avoid licence fees. Before you hire anyone, we recommend answering three questions:
Our LMS cost calculator gives an indicative range, and LMS consulting helps if you are still deciding.
A team that has built LMS products will discuss SCORM runtime quirks, xAPI statement design and LTI 1.3 security without hesitation.
Enterprise buyers will send security questionnaires. Your team should design for SSO, audit logging, data separation and least privilege from the start. Our multi-tenant LMS architecture guide explains the trade-offs.
You should own the code, the repositories and the cloud accounts. Documentation and tests should be good enough for another team to continue.
A short, fixed-price discovery phase produces architecture, estimates and risks, and shows you how the team works before you commit to a full build.
Learning standards explained: SCORM vs xAPI vs cmi5.
New builds usually start with a fixed-price discovery phase, followed by either fixed-price milestones or a dedicated team on a monthly plan. Take-overs start with a code audit. You get a written estimate after the free technical call, and our LMS cost calculator gives an early range.
Yes. We start with an architecture and security audit, document what we find, fix the riskiest issues and then continue development. You keep the audit report whatever you decide.
Yes: SCORM 1.2 and 2004 players, xAPI with your own or a third-party LRS, cmi5 launch and LTI 1.3 as a tool or a platform.
We work in the stack that suits the product and your team: commonly PHP with Laravel, Node.js or Python on the backend, React or Vue on the front end, and MySQL or PostgreSQL, deployed with Docker on AWS or your own servers.
You do. The contract assigns all code and intellectual property to you, and we work in repositories and cloud accounts you control.
If your workflows are standard, extending an existing LMS is usually faster and cheaper. We will tell you honestly. If you are evaluating platforms, we also build LMS Advisor, an enterprise LMS; we always disclose this and compare it fairly.
Yes: a progressive web app or native apps on top of your platform's API, with offline access, notifications and secure sign-in where needed.
Free estimate
New build or existing system, your users and your timeline. A senior engineer will reply with questions or a first estimate.
A practical guide to single sign-on for your LMS: choosing SAML or OpenID Connect, provisioning users with JIT or SCIM, mapping roles and cohorts, an…
How to architect a multi-tenant LMS: instance, shared database and database-per-tenant models, platform options like Moodle Workplace and IOMAD, and…
SCORM, xAPI and cmi5 solve different tracking problems, and LTI 1.3 solves a different one again. Here is how they compare and which to choose for yo…