For the IT administrator

Signing in with the school’s Google account

If your school uses Google Workspace for Education, pupils can sign in with the account they already have, and a teacher can bring their whole class over from Google Classroom in one go. For that you switch on two things in the Admin console. That is the whole job, and it is set out below in the order you do it.

No Google at your school? Then pupils sign in with a class code, and there is nothing for you to set up.

Pupils

Letting pupils under 18 sign in

Google blocks outside apps for everyone designated as under 18. In primary and secondary schools that is every pupil, unless you have designated them as 18+. A pupil who taps Sign in with Google then sees Access blocked (Error 400: admin_policy_enforced). You fix that on the organisational unit (OU) of your pupils, in one of two ways.

The menu names below are Google’s own. If your Admin console is set to another language, they read slightly differently.

Option 1: every app that only asks to sign in. This is the broadest, and you do it once.

  1. In the Admin console, go to Security › Access and data control › API controls.
  2. Under Unconfigured third-party apps, pick the OU of your pupils.
  3. Choose Allow users to access third-party apps that only request basic info needed for Sign in with Google.

Basic info is a name, an email address and a profile picture. We ask for nothing more when signing in, and we do not use the picture.

Option 2: only this app. If you would rather keep everything else closed, put only us on the list.

  1. Go to Security › Access and data control › API controls › Manage App Access.
  2. Choose Configure new app and search for Learnbits.app, the name the app has at Google, or paste the client ID from the block below.
  3. Pick the OU of your pupils and set access to Trusted. Limited works too.

A change can take up to 24 hours to apply everywhere. If a pupil still sees Access blocked after that, wait a day before you look further. Where the law asks for parental consent, Google places that with the school.

Teachers

Bringing the class over from Classroom

A teacher can bring their class over from Google Classroom in one go: the names, and the link that lets each pupil sign in with Google from then on. That has its own switch, separate from the app access above. If it is off, a teacher cannot share their class, even when the app is trusted.

  1. In the Admin console, go to Apps › Google Workspace › Classroom.
  2. Open Data access.
  3. Switch Classroom API on, for the whole domain or for the OU of your teachers.

Pupils do not need that switch. The teacher does the import, and a pupil never gives us access to Classroom.

Requests

A teacher can set it up for you

Since November 2024 a teacher can request access on behalf of their pupils to an app that has not been configured yet. That works in Education Fundamentals, Standard, Plus and the Teaching and Learning Upgrade.

You see the request in the Admin console under Apps pending review and approve it there. Useful when a teacher runs into it in class before you do: they ask, and all you have to do is say yes.

Passing it on

Everything you need, in one block

Copy it and send it on, or keep it next to the Admin console.

App
Learnbits.app (at Google); on the web learnbits.app
OAuth client ID
to follow
Sign-in, pupils and teachers
openid, email, profile
Class import, teachers only
https://www.googleapis.com/auth/classroom.courses.readonly, https://www.googleapis.com/auth/classroom.rosters.readonly
Posting an assignment in Classroom, teachers only
https://www.googleapis.com/auth/classroom.coursework.students
Classroom API
on, under Apps › Google Workspace › Classroom › Data access
Privacy policy
https://learnbits.app/privacy

The client ID is to follow. Until then, search by name under Manage App Access.

Data

What we get from Google, and what we do not

When signing in we only get the name, the email address and the Google ID of whoever signs in. That tells us which pupil it is.

For the import the teacher gives permission at the moment they press the button. We fetch the names of their courses, and for the course they pick, the names, Google IDs of the pupils. Once, at that moment. Nothing runs in the background, and we keep no token: fetching again later means giving permission again.

For an assignment we only post the assignment the teacher makes with us in their course, with a link in it. We do not read or change any other assignment.

We sell nothing, show no adverts and train no AI with it. When the teacher deletes a pupil or a class, the link with Google goes with it. The full account is on the privacy page.