Account, Pricing & Access

SAML Single Sign-On (SSO) setup

PathologyLabTraining supports SAML 2.0 single sign-on so your members can sign in with their institutional credentials (Microsoft Entra ID, Okta, Shibboleth, Google Workspace, or any SAML-compliant identity provider).

We are a registered service provider on the UK Access Management Federation, so UK universities and NHS bodies that are federation members can connect through the federation's trust fabric.

How to configure

Import our published metadata into your identity provider. It carries the entity ID, assertion consumer service and single logout endpoints, NameID formats, certificate and bindings in one step.

Quick facts (if your IdP asks)

Setting Value
Entity ID (SP) https://pathologylabtraining.co.uk/saml/sp
Service name PathologyLabTraining - Biomedical Science Laboratory Training
NameID formats supported persistent, transient
Signature algorithm RSA-SHA256
Certificate, ACS, SLS Inside the published metadata above

Attributes we use

Release the following attributes to our entity ID:

If no name attributes are released, the user's display name falls back to their common name, principal name or the local part of the identifier. Users are not asked to enter a name during sign-in; they can set their display name in Account Settings afterwards.

Enabling SSO for your organisation

  1. Register your organisation on PathologyLabTraining (see Organisation administration).
  2. The organisation owner opens Organisation dashboard → Settings → Single Sign-On (SSO) and starts the request, or emails us directly.
  3. Send us your identity provider's metadata (a URL or file) and tell us which attributes you release.
  4. We configure the connection and test it with one of your users before enabling it for everyone.

Contact [email protected] with the subject "SSO setup: {your organisation}".

What your users see

  1. On the login page, under Institutional access, the user clicks Continue with UK Federation.
  2. They search for your institution and select it.
  3. They are redirected to your identity provider, sign in as usual, and are returned to PathologyLabTraining signed in with your organisation's access applied.

For a link that goes straight to your organisation's sign-in, use /auth/saml/login/{organisation id}; we give you the exact link when SSO is enabled.

Single logout

We support SP-initiated single logout. When a user signs out of PathologyLabTraining we send a LogoutRequest to your single logout endpoint. If your identity provider does not support it, users are signed out of PathologyLabTraining only and their institutional session continues.

Common issues

All SSO enquiries, including metadata exchange, attribute mapping, NameID changes, certificate rollovers and federation queries, go to [email protected].