SAML-based single sign-on (SSO) allows you to integrate an identity provider (IDP) of your choice. Once configured, users will be forced to sign in to Benchling through the IDP. This lets you tie all accounts to a centralized directory, enforce password requirements, implement multi-factor authentication, and more.

Note that SAML SSO is only available on certain Benchling product editions.

Step 1: Configure your identity provider (IDP)

Benchling supports any IDP that implements the SAML 2.0 protocol.

Below you can find help pages for individual IDPs that Benchling has tested with:

If you don't see your IDP listed above, you can follow the instructions for generic SAML integrations.

Step 2: Send configuration information to Benchling

Once you've configured your IDP, you should have a metadata URL (some providers do not offer a URL and offer only a metadata file usually called metadata.xml). Please send that URL (or file) over to your Benchling customer success representative.

Once Benchling support has received the metadata, we'll turn on SAML in "soft launch" mode. In this mode, we'll be able to verify that SAML works but users will not yet be forced to log in via SAML.

Step 3: Verify SAML integration

Benchling support will send you instructions on how to verify that SAML is working. Once confirmed to be working, ensure that all users have access to Benchling from within your IDP. (Be careful to double check this, as any user who does not have access will be locked out of Benchling once SAML is fully enabled.)

Step 4: Enforce SAML for all users

Finally, Benchling support will enforce SAML for all users. All future sign-ons will go through your IDP instead of the normal username and password flow.

