Account, Pricing & Access
PathologyLabTraining supports SAML 2.0 single sign-on so your members can sign in with their institutional credentials (Microsoft Entra ID, Okta, Shibboleth, Google Workspace, or any SAML-compliant identity provider).
We are a registered service provider on the UK Access Management Federation, so UK universities and NHS bodies that are federation members can connect through the federation's trust fabric.
Import our published metadata into your identity provider. It carries the entity ID, assertion consumer service and single logout endpoints, NameID formats, certificate and bindings in one step.
https://pathologylabtraining.co.uk/saml/sp/metadatapathologylabtraining.co.uk in your federation tooling.| Setting | Value |
|---|---|
| Entity ID (SP) | https://pathologylabtraining.co.uk/saml/sp |
| Service name | PathologyLabTraining - Biomedical Science Laboratory Training |
| NameID formats supported | persistent, transient |
| Signature algorithm | RSA-SHA256 |
| Certificate, ACS, SLS | Inside the published metadata above |
Release the following attributes to our entity ID:
mail (required): the user's email addressgivenName and sn: first name and surnameeduPersonPrincipalName: used as a stable identifier where releasededuPersonScopedAffiliation (optional): member, staff, student and so onIf no name attributes are released, the user's display name falls back to their common name, principal name or the local part of the identifier. Users are not asked to enter a name during sign-in; they can set their display name in Account Settings afterwards.
Contact [email protected] with the subject "SSO setup: {your organisation}".
For a link that goes straight to your organisation's sign-in, use /auth/saml/login/{organisation id}; we give you the exact link when SSO is enabled.
We support SP-initiated single logout. When a user signs out of PathologyLabTraining we send a LogoutRequest to your single logout endpoint. If your identity provider does not support it, users are signed out of PathologyLabTraining only and their institutional session continues.
emailAddress NameID. We accept persistent or transient only, in line with UK Federation guidance.All SSO enquiries, including metadata exchange, attribute mapping, NameID changes, certificate rollovers and federation queries, go to [email protected].