Assign IP by Entry Point
In this article we will show you how to set up IP assignment by Entry Point, so that the users of an institution enter the store automatically from their network and are also identified individually.
⚠️ IP assignment is available on the Enterprise plan.
HOW IS IT DIFFERENT FROM ASSIGNING THE IP TO A USER?
- IP assignment to a user: all the users who enter from that IP share the same account. Reading statistics are shown in aggregate.
- IP assignment by Entry Point: the IP is assigned to an Entry Point and the network (or the proxy) tells us who each person is through a header. Each reader has their own account, with individual reading statistics, notes and highlights.
It works for direct access (for example, from a campus network) and through a proxy such as EzProxy.
PREREQUISITES
Before you start, ask your client for:
- The IP addresses or IP ranges from which their users will connect. If they use a proxy, the proxy IP.
- That their network or proxy sends, on every login, at least one of these headers:
X-Username: the user's email.X-External-Id: an institutional identifier (for example, an ID number), up to 200 characters. Use it when the proxy does not know the email.
SETUP
1. Go to Control Panel > Settings > Integrations.
2. Create a new Entry Point for IP login, or select an existing one.
3. Use the Assign IP range option to load the IPs or ranges your client gave you.
4. Choose how users will access the content:
- Allow full access to the publications: access lasts only for the browser session and does not work in the mobile or desktop apps.
- Automatically assign a plan: users receive permanent access, which lets them read in the browser and also in the mobile and desktop apps.
5. Save your changes.
💡 Choose Assign a plan if your users need to read from the apps or keep access outside the browser session.
HOW EACH USER IS IDENTIFIED
When a person connects from an authorized IP and the request carries one or both headers:
- We look for their account by
X-External-Idfirst and, if we do not find it, byX-Username. - If no account exists, one is created with the data received. An account created only with
X-External-Idhas no email. - If the account is found by email and does not have an external identifier yet, the one received is attached to it. This links users you had already created from the Control Panel.
- If a value is not valid, it is ignored and the other one is used. The login is rejected only when neither of them can be used.
⚠️ An identifier belongs to a single account. If two Entry Points send the same identifier, both enter the same account.
LINK FOR YOUR USERS
Users who connect from a configured IP will be authenticated automatically when they access the library (/library), a publication page or the reader. If they log out, they will be authenticated again when they return to protected content.
To build the link your client will place on their campus or intranet, follow the same steps as in Assign IP ranges.
TROUBLESHOOTING
Add ?debug=true to the IP login URL to see information about the connection:
https://your-store.publica.la/auth/ip?debug=true
That screen shows the detected IP and, with Entry Point, also the request headers. This way you can confirm that X-Username or X-External-Id arrives and which value it carries.
| Symptom | Likely cause | What to do |
|---|---|---|
| The login form appears | The IP does not match the configured one | Confirm the outgoing IP with your client and compare it with the debug screen |
| The login form appears with the correct IP | The request carries no valid identity header | Ask your client to make their network or proxy send X-Username or X-External-Id |
| Two people share the same account | The proxy sends the same identifier for everyone | Check that the identifier is different for each user |
If these checks do not help you find the problem, take a look at this troubleshooting tool.
💡 Technical reference: the details of the headers and the flow are in the integrations documentation: https://docs.publica.la/auth-integrations/auth-ip-integrations-tenants
We hope this tutorial has been easy for you. If you have questions, write to us at [email protected].