Feature availability
- Platforms: Desktop
- Plans: Select School and Business plans
- Team roles: Administrators
Important: The BioDigital team must first enable SSO for your account. If you are interested in enabling SSO for your team, contact your dedicated Account Manager or our Customer Experience team.
Use this guide to configure Shibboleth SAML single sign-on (SSO) for your BioDigital Human team. Once enabled, eligible users can sign in using their Shibboleth credentials instead of a separate BioDigital password.
Before you begin
Before starting configuration, make sure:
- Your organization uses Shibboleth
- You have administrator access to your Shibboleth Identity Provider (IdP)
- You also have administrator access to your BioDigital Human team account
Step 1: Register the BioDigital Human in Shibboleth
Start by registering the BioDigital Human as a Service Provider (SP) in your Shibboleth Identity Provider (IdP).
Configure your Shibboleth SP connection using the following values:
| Setting | Value |
| Assertion Consumer Service (ACS) URL | https://human.biodigital.com/ws/user/sign/in/shibboleth |
| Entity ID | https://human.biodigital.com/shibboleth/metadata |
Configure SAML attribute release
Configure your Shibboleth IdP to release the following SAML 2.0 attributes to the BioDigital Human (via your default federation policy and/or a resource-specific release policy):
| User Information | SAML Attribute |
| Unique user identifier (required) |
or
|
| Email (required) |
urn:oid:0.9.2342.19200300.100.1.3 (mail) |
| First name (recommended) |
urn:oid:2.5.4.42 (givenName) |
| Last name (recommended) |
urn:oid:2.5.4.4 (sn) |
Important: Configure your IdP to use assertion-level signing, as the BioDigital Human expects the SAML assertion to be signed.
Note: If the mail attribute cannot be released, you may instead use eduPersonPrincipalName (urn:oid:1.3.6.1.4.1.5923.1.1.1.6). However, mail is the preferred email attribute whenever possible.
Step 2: Collect your Shibboleth metadata URL
To complete SSO configuration in the BioDigital Human, you will need your Shibboleth IdP metadata URL:
- Locate your Shibboleth IdP metadata URL.
- Copy the URL and store it for use in Step 3.
Note: The process for locating your metadata URL varies depending on how your organization has deployed and configured Shibboleth. If you are unsure where to find it, consult your organization's Shibboleth administrator or documentation.
Step 3: Configure SSO in the BioDigital Human
The final step is to create your SSO configuration in the BioDigital Human using the metadata URL from Shibboleth:
- Log in to the BioDigital Human.
- Click the profile icon in the upper-right corner and select Team from the drop-down menu.
- Click Manage.
- Open the Team Access tab and scroll down.
- Under Single Sign-On (SSO) Configuration, click + Add SSO Configuration.
- Under SSO Provider, select Shibboleth (SAML) from the drop-down menu.
- Enter a Configuration Name.
- Enter the metadata URL you copied in Step 2 into the Metadata URL field under Shibboleth (SAML) Configuration.
- Check the box next to Enable this SSO configuration.
- Click Save Configuration.
Success—your Shibboleth SAML integration is now active!
What to expect after SSO is enabled
Existing users
The next time an existing team member logs in, they will be prompted to link their BioDigital Human account to your organization's identity provider.
Once linked, future logins will occur through single sign-on (SSO).
New users
New team members will be prompted to authenticate through your organization's identity provider when creating their BioDigital Human account.
If SSO is later disabled, these users will be required to create a BioDigital password.
Administrator fallback login
In the event of an SSO failure, administrators can still log in using their original BioDigital password.
For this reason, password setup remains required for all Administrator accounts.