Six steps from mock to live mirror
Municipality enables. School picks surfaces. Mock-mode validates. When mTLS certificates land, you go live.
- 1
The municipality enables the Aula integration in its tenant
A super-admin enables the feature. Until then, schools don't see it.
- 2
The school enters its institution code (mock-mode)
We validate the code against KOMBIT discovery. Mock-mode runs without real Aula calls.
- 3
UNI-Login roster sync links the profiles
Teachers, students and parents link via unilogin_id — not name match.
- 4
School admin picks which surfaces are mirrored
Messages, announcements, calendar and after-school each have their own toggle. Enable one at a time.
- 5
Mock-mode test — verify with no risk
Mirrors are logged in the queue table but not sent to Aula. Ideal before mTLS certificates.
- 6
Go live — mTLS certificates land, toggle flips
AULA_CLIENT_CERT_PEM and AULA_CLIENT_KEY_PEM are stored as secrets. The school is live.
What the school admin panel looks like
FAQ
What happens if Aula is down?→
The primary write to SkoleElev happens first. The Aula mirror is queued and retried up to 5 times with back-off.
Can we roll back?→
Yes — flip the toggle off and mirroring stops immediately. Existing Aula messages stay in Aula.
What data flows to Aula?→
Only the surfaces the school has actively enabled. Every mirror event is logged in the message sync with an audit trail.
Does it run without KOMBIT certificates?→
Yes — mock-mode is default. Mirrors are logged but not sent. Only once AULA_CLIENT_CERT_PEM and AULA_CLIENT_KEY_PEM are stored do you go live.

