For the IT administrator
Signing in with the school’s Google account
If your school uses Google Workspace for Education, pupils can sign in with the account they already have, and a teacher can bring their whole class over from Google Classroom in one go. For that you switch on two things in the Admin console. That is the whole job, and it is set out below in the order you do it.
No Google at your school? Then pupils sign in with a class code, and there is nothing for you to set up.
Pupils
Letting pupils under 18 sign in
Google blocks outside apps for everyone designated as under 18. In primary and secondary schools that is every pupil, unless you have designated them as 18+. A pupil who taps Sign in with Google then sees Access blocked (Error 400: admin_policy_enforced). You fix that on the organisational unit (OU) of your pupils, in one of two ways.
The menu names below are Google’s own. If your Admin console is set to another language, they read slightly differently.
Option 1: every app that only asks to sign in. This is the broadest, and you do it once.
- In the Admin console, go to Security › Access and data control › API controls.
- Under Unconfigured third-party apps, pick the OU of your pupils.
- Choose Allow users to access third-party apps that only request basic info needed for Sign in with Google.
Basic info is a name, an email address and a profile picture. We ask for nothing more when signing in, and we do not use the picture.
Option 2: only this app. If you would rather keep everything else closed, put only us on the list.
- Go to Security › Access and data control › API controls › Manage App Access.
- Choose Configure new app and search for Learnbits.app, the name the app has at Google, or paste the client ID from the block below.
- Pick the OU of your pupils and set access to Trusted. Limited works too.
A change can take up to 24 hours to apply everywhere. If a pupil still sees Access blocked after that, wait a day before you look further. Where the law asks for parental consent, Google places that with the school.
Teachers
Bringing the class over from Classroom
A teacher can bring their class over from Google Classroom in one go: the names, and the link that lets each pupil sign in with Google from then on. That has its own switch, separate from the app access above. If it is off, a teacher cannot share their class, even when the app is trusted.
- In the Admin console, go to Apps › Google Workspace › Classroom.
- Open Data access.
- Switch Classroom API on, for the whole domain or for the OU of your teachers.
Pupils do not need that switch. The teacher does the import, and a pupil never gives us access to Classroom.
Requests
A teacher can set it up for you
Since November 2024 a teacher can request access on behalf of their pupils to an app that has not been configured yet. That works in Education Fundamentals, Standard, Plus and the Teaching and Learning Upgrade.
You see the request in the Admin console under Apps pending review and approve it there. Useful when a teacher runs into it in class before you do: they ask, and all you have to do is say yes.
Passing it on
Everything you need, in one block
Copy it and send it on, or keep it next to the Admin console.
- App
- Learnbits.app (at Google); on the web learnbits.app
- OAuth client ID
- to follow
- Sign-in, pupils and teachers
- openid, email, profile
- Class import, teachers only
- https://www.googleapis.com/auth/classroom.courses.readonly, https://www.googleapis.com/auth/classroom.rosters.readonly
- Posting an assignment in Classroom, teachers only
- https://www.googleapis.com/auth/classroom.coursework.students
- Classroom API
- on, under Apps › Google Workspace › Classroom › Data access
- Privacy policy
- https://learnbits.app/privacy
The client ID is to follow. Until then, search by name under Manage App Access.
Data
What we get from Google, and what we do not
When signing in we only get the name, the email address and the Google ID of whoever signs in. That tells us which pupil it is.
For the import the teacher gives permission at the moment they press the button. We fetch the names of their courses, and for the course they pick, the names, Google IDs of the pupils. Once, at that moment. Nothing runs in the background, and we keep no token: fetching again later means giving permission again.
For an assignment we only post the assignment the teacher makes with us in their course, with a link in it. We do not read or change any other assignment.
We sell nothing, show no adverts and train no AI with it. When the teacher deletes a pupil or a class, the link with Google goes with it. The full account is on the privacy page.