Single Sign-On (SSO) with BioRender Single Sign-On (SSO) with BioRender

Single Sign-On (SSO) with BioRender

Single sign-on (SSO) lets your members sign in to BioRender using your organization's existing identity provider - the same login they use for other work tools. No separate BioRender password.

This article covers who can set up SSO, what we need from you, what the process looks like, and how to request new setups or changes to an existing setup.

Table of Contents

Before you start: eligibility

SSO is available to organizations that meet all of the following:

  1. You have a paid BioRender organization subscription (Enterprise, Academic Organization, Industry Team) 
  2. Your purchase order (PO) is signed
  3. Your organization account has been created in BioRender and assigned to a Customer Success Manager

⚠️ We will not be able to start SSO setup unless these have been completed. If your subscription isn't live yet, there's no organization for us to connect your identity provider to. Talk to your BioRender Account Executive or Customer Success Manager first - they'll let you know when you're ready.

Not sure? If you don't know who your BioRender Customer Success Manager is, you're likely not at this stage yet. Feel free to reach out to our Support team for further guidance.

What you'll need

Have these ready before you submit a request. Missing information is the single biggest cause of delays.

What we'll need Where to find it
Organization name in BioRender

Your organization name as it appears in your BioRender account. How to find this (*note: you'll need to have Admin permissions):

  1. Navigate to your Admin settings

2. Navigate to "Account Overview & Users". Copy and paste your "Organization Name"

Admin (or IT Admin) name and email The person who will administer the BioRender organization.
Your identity provider (IdP) Any IdP that supports SAML 2.0 — for example Okta, Microsoft Entra ID, Google Workspace, or Shibboleth.
IdP metadata Your metadata XML file or metadata URL.
Target go-live date If you have a deadline, tell us upfront.

What we support

  • Authentication system: BioRender uses Auth0, an industry-leading authentication and authorization platform that allows us to maintain high security standards.
  • Identity providers: BioRender is compatible with all identity providers that support SAML 2.0 — including Okta, Microsoft Entra ID, Google Workspace, and Shibboleth.
  • Login methods: BioRender supports a single login method only. Once SSO is set up, all users in your organization are required to log in with SSO. If SSO is not set up, users log in with email and password. There is no per-user opt-out.
  • We support both:
    • SP-initiated (Service Provider Initiated): users go to BioRender.com and your IdP authenticates them.
    • IdP-initiated (Identity Provider Initiated): users log in to your IdP and select the BioRender app.
  • Provisioning: BioRender supports Just In Time (JIT) provisioning - user accounts are created automatically on first sign-in.
  • Certificates: See “Certificate renewal” below.
  • Attributes (Required/Optional)
    • First name: Required
    • Last name: Required
    • Email: Required
    • Department: Optional
    • Role: Optional
    • Cost Center: Optional

How to request SSO setup

  1. Submit a request by filling out this form. Everything from the "What you'll need" table above will need to be included.
  2. We review and reach out. Our SSO specialist reviews your request and contacts your admin or IT contact directly to exchange configuration details.
  3. We configure the connection. We set up the connection on BioRender's side using your metadata. If anything in your configuration needs adjusting, we'll tell you exactly what to change on your end.
  4. We schedule a test. We coordinate a time with you to test the connection end to end before it affects anyone.
  5. We plan communication to your users (existing organizations only - see below).
  6. SSO goes live. Once tested, we enable SSO on your license and close your request.

How long does it take?

It varies. Straightforward setups can be done in a day. More complex configurations - or ones where we're waiting on information from your IT team - can take a few weeks. The fastest setups are the ones where the requester provides complete information upfront and has authority to make IdP changes.

New organizations vs. existing organizations

If your BioRender organization is new or empty: SSO setup is simple. We configure the connection, test it, and your users sign in with SSO from day one.

If your organization already has users signing in with a BioRender username and password: switching to SSO changes how everyone logs in. Because BioRender supports one login method at a time, every user in your organization moves to SSO at the same time - their existing email-and-password login will stop working.

We'll work with you and your Customer Success Manager on a communication plan before we implement the switch - usually an email to your users explaining the change and when it takes effect. Some users may need individual handling depending on how their account is set up.

Tell us in your request how many active users you have so we can plan for this.


Other SSO requests

Already have SSO set up? All requests should be submitted through this form. These are the most common follow-up requests and who should submit.

Certificate renewal

Your SSO signing certificate expires periodically. When it does, your users will be blocked from signing in. If we spot the upcoming expiry first, we'll contact your admin directly - usually around 30 days out. If your IdP notifies you first, fill out the form to schedule the update. Who submits: your admin or IT contact. Don't wait. Coordinating a certificate swap takes time, and an expired certificate locks your whole organization out.

Changing your identity provider

Migrating from one IdP to another (for example, Entra ID to Okta) means reconfiguring everything: attributes, certificate, and mapping. Treat this like a new setup and give us as much lead time as possible. Who submits: your admin or IT contact.

Troubleshooting an existing SSO connection

Users can't sign in, or something has stopped working. Include what's happening, which users are affected, when it started, and any error messages. Who submits: your admin or IT contact.

Security questionnaire

If your security or procurement team needs details on how BioRender handles SSO, check this article first - it should answer most standard questions. If you still need a questionnaire completed, submit a request and we'll help. Who submits: your admin, IT, or security contact.


Frequently asked questions

Can we set up SSO before we sign? 

No. We need an active, paid organization to connect your identity provider to.

Can we require SSO for everyone, or is it optional per user? 

SSO applies to your whole organization. BioRender supports one login method at a time - once SSO is live, all users sign in through your IdP. There's no per-user opt-out.

Which identity providers do you support? 

Any provider that supports SAML 2.0.

Do users need to be created in BioRender before they can sign in? 

No. We support Just In Time (JIT) provisioning, so accounts are created on first sign-in.

Can we test SSO in a sandbox first? 

No, however if you are experiencing issues, we can always schedule a supportive call and provide next steps to resolve the issue. 

Do users lose their existing files when we switch to SSO? 

No, you will never lose your files. If you cannot see your files in your account, it’s possible a duplicate account was created. Reach out to our Support team at support@biorender.com if you need further investigation. 


Still need help?

Contact your BioRender Customer Success Manager, or email sso@biorender.com

What's new →
Discover more in BioRender
 
 BioRender AI

Draft custom figures in seconds from a text prompt.

Learn more → Browse help articles →
 
 Graphing

Turn raw data into journal-quality graphs in minutes.

Learn more → Browse help articles →

Was this article helpful?

0 out of 0 found this helpful