Account, Pricing & Access
PathologyLabTraining supports SAML 2.0 single sign-on so your members can sign in with their institutional credentials (Microsoft Entra / Azure AD, Okta, Shibboleth, Google Workspace, or any SAML-compliant IdP).
We are also registered on the UK Access Management Federation for trusted federation between UK universities and NHS bodies.
Import our published metadata into your IdP. Every modern IdP supports this — it pulls the entity ID, ACS, SLS, NameID formats, certificate, and supported bindings in one step. No manual entry needed.
https://pathologylabtraining.co.uk/saml/sp/metadatapathologylabtraining.co.uk); no manual configuration needed.| Setting | Value |
|---|---|
| Entity ID (SP) | https://pathologylabtraining.co.uk/saml/sp |
| NameID formats supported | persistent, transient |
| Signature algorithm | RSA-SHA256 |
| Certificate, ACS, SLS | Inside the published metadata above — your IdP imports them automatically. |
Map the following attributes on your IdP (names not strict — your administrator can rename):
email (required) — primary user identifierfirstName — given namelastName — family nameeduPersonAffiliation (optional, UK Fed) — member / staff / studenteduPersonPrincipalName (optional) — for federated environmentsIf you cannot set firstName/lastName, the user will be prompted to provide them on first sign-in.
We maintain a per-organisation SAML configuration in our database. Your organisation admin (on PathologyLabTraining) requests SSO setup via Admin Dashboard → Settings → SSO. The PathologyLabTraining team then:
/saml-acs/{organizationId})If your institution is on the UK Federation, we are listed as:
https://pathologylabtraining.co.uk/saml/spYour IdP can pull our metadata directly from the UK Federation trust fabric without manual configuration.
/loginFor organisation-specific deep links, use /auth/saml/login/:organizationId.
We support SP-initiated SLS. When a user signs out of PathologyLabTraining, we POST a LogoutRequest to your SLS endpoint. If your IdP does not support SLS, configure SP-only logout — users will be signed out of PathologyLabTraining but their IdP session continues.
emailAddress NameID. We removed emailAddress support per UK Fed guidance; use persistent or transient.For setup help, contact us via your account manager or [email protected] with the subject "SSO setup — {your organisation}".
All SAML SSO enquiries — initial setup, IdP metadata exchange, attribute mapping, NameID changes, certificate rollovers, federation queries — go through [email protected]. The message is routed to the responsible platform admin within one working day.