Logging Into the Staff Web Client
Getting into ILLiad's Staff Web Client is straightforward, but the exact method depends on how your institution has configured authentication. You might sign in with a username and password, use your institutional credentials through single sign-on (SSO), or complete a multi-factor authentication (MFA) step with an authenticator app. This page walks through each option so you know what to expect.
Reaching the Login Screen
Navigate to your institution's Staff Web Client URL. It lives at the /illiadstaff path on your ILLiad server — for example:
https://[institution].illiad.atlas-sys.com/illiadstaff
You'll see a login screen with a Username field, a Password field, and a Logon button. Enter your username and password to sign in — the screen does not pre-fill or store your credentials.
Using Your ILLiad Username and Password
If your library uses ILLiad's built-in authentication, sign in with the credentials your administrator created for you. Enter your username and password and select Logon.
Password requirements are set by your institution's ILLiad configuration, not by the Web Client. If you need to know your organization's requirements, or you need a password reset, contact your ILLiad system administrator.
If your account requires a password reset, the login screen will display:
A password reset is required for this account.
This message can appear at any login, not only your first one. The Web Client does not include an in-client change-password screen — work with your administrator to reset the password.
Single Sign-On (SSO)
Many institutions use single sign-on so that staff use the same institutional credentials for ILLiad that they use for other systems.
When SSO is configured, the login page shows a Logon with [provider] button (for example, "Logon with Shibboleth"). Select it, complete your institution's login at the provider's page, and you'll be returned to ILLiad.
The first time you sign in through SSO, ILLiad needs to connect your institutional identity to your ILLiad staff account. This linking is self-service: you'll be asked to enter your existing ILLiad staff username and password once to confirm the link. After that, future SSO logins go through automatically.
Multi-Factor Authentication (MFA)
How you complete MFA depends on how you sign in:
If you sign in with SSO, multi-factor authentication is handled by your institution's identity provider as part of the SSO login — follow your provider's prompts. The Web Client does not add a separate step.
If you sign in with an ILLiad username and password and your administrator has enabled MFA, the Web Client adds its own authenticator-app step. It uses time-based one-time passcodes (TOTP) from an app such as Microsoft Authenticator, Google Authenticator, Authy, or 1Password. The first time, the setup screen shows a QR code to scan (or a manual entry key to type), and on every login after that you enter the current 6-digit code from your app:
Please enter a one-time code from your Authenticator app.
If you lose access to your authenticator app, an administrator must reset your MFA before you can set it up again:
If you have lost access to your Authenticator app, please contact your system administrator.
For setup and administration details, see Web Client Authentication.
Session Timeout
While you are actively working, you stay logged in. After a period of inactivity — approximately 14 minutes — the Web Client logs you out to protect patron data. About one minute before that, a warning prompt asks whether you want to stay logged in. Respond to the prompt to keep your session active; otherwise you'll need to log in again. This inactivity timeout is a fixed behavior of the Web Client.
When Things Don't Work
Most login problems are easy to resolve.
Invalid username or password – Check that Caps Lock is off and that you're using your staff credentials. If you still can't get in, contact your administrator to confirm your account is active or to reset your password.
Account locked – If your account is locked, the login screen shows:
This account is locked.
Contact your ILLiad system administrator to have the account unlocked.
SSO problems – If SSO isn't working, try clearing your browser's cookies and cache, or use a private/incognito window. If the problem persists, check whether colleagues are affected and contact your administrator.
MFA troubles – Authenticator-app codes are time-sensitive. Make sure your device's clock is set to update automatically. If a code isn't accepted, wait for the next code to generate. If you've lost access to your authenticator app, contact your system administrator.
Keeping Your Account Secure
Good security habits protect both your account and your patrons' information:
- Use a unique password for ILLiad rather than reusing one from another service.
- Lock your computer whenever you step away, even briefly.
- On a shared or public computer, log out and close the browser window when you're finished.
- If a login page ever looks suspicious or asks for information beyond what's described here, stop and verify you're on your institution's correct ILLiad URL.
Getting Help
Your ILLiad system administrator is your go-to person for access issues — resetting passwords, unlocking accounts, helping with MFA, and confirming your permissions are set correctly. If you can't get in, contact them.
Once you're successfully logged in, your permissions determine what you'll see and what you can do. Continue to Understanding User Permissions.