Updating OverDrive Password Requirements in Koha and Aspen

Updating OverDrive Password Requirements in Koha and Aspen

This article discusses how to require PIN/password for patron access to OverDrive resources, pending communication from OverDrive requiring patron login to be in place by October 15, 2026. We encourage you to use the Table of Contents to jump to a specific section or Control+F to search for keywords. 

Updating SIP settings in Koha

For Koha libraries, SIP settings can be updated directly from the staff client in the SIP2 (Self Service Circulation) settings module in Koha administration for superlibrarians or staff with the sip2 staff permission, introduced in the 25.11 release. From the SIP2 landing page, active SIP accounts can be accessed from the Accounts menu. ByWater will often set up a SIP connection with a naming convention beginning with something like sip_libby or sip_overdrive, depending on how a partner initiated the request, but libraries may have different internal naming conventions. Once the Overdrive/Libby SIP account has been identified, selecting it will reveal the settings, with an option to Edit. The setting for "Allow empty passwords" should be set to "No" if it was not already.

Updating OverDrive integration settings for OPAC/discovery layer

For libraries using the Koha OPAC integration for OverDrive, the Koha system preference OverDrivePasswordRequired should be changed to "Required."

If the integration is set up through Aspen, the relevant setting can be found in Aspen Administration -> OverDrive -> Settings. From there, the Authentication and Advantage Information box has a column labeled "Is a Pin Required to log into Overdrive website?" The setting can be updated if not; historically, libraries were encouraged to match this setting to their Overdrive website login settings, so many libraries will need to update this configuration with the new PIN/password requirement.

ByWater partner libraries using Aspen with another ILS need to check in with their vendor to ensure their ILS SIP connection is compliant with the new policy as well.

Once these changes are in place, libraries should notify OverDrive that ILS settings have been updated to comply with new requirements.