Benchling · Authentication Profile
Benchling Authentication
Authentication
Benchling secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
Life SciencesBiotechR&DMolecular BiologyLaboratory Information ManagementElectronic Lab NotebookAssay ManagementInventory ManagementSequence ManagementExperiment WorkflowsRESTWebhook
Methods: http, oauth2
Schemes: 2
OAuth flows: clientCredentials
API key in:
Security Schemes
basicApiKeyAuth http
scheme: basic
oAuth oauth2
· flows: clientCredentials
Source
Authentication Profile
generated: '2026-08-15'
method: searched
source: openapi/benchling-v3-openapi.yaml + openapi/*.yml securitySchemes, enriched from https://docs.benchling.com/docs/authentication
and https://docs.benchling.com/docs/getting-started-benchling-apps, read 2026-08-15.
summary:
types:
- http
- oauth2
oauth2_flows:
- clientCredentials
schemes:
- name: basicApiKeyAuth
type: http
scheme: basic
description: Use issued API key for standard access to the API
sources:
- openapi/benchling-aa-sequences-api-openapi.yml
- openapi/benchling-apps-api-openapi.yml
- openapi/benchling-assay-results-api-openapi.yml
- openapi/benchling-assay-runs-api-openapi.yml
- openapi/benchling-audit-api-openapi.yml
- openapi/benchling-authentication-api-openapi.yml
- openapi/benchling-blobs-api-openapi.yml
- openapi/benchling-boxes-api-openapi.yml
- openapi/benchling-codon-usage-tables-api-openapi.yml
- openapi/benchling-connect-api-openapi.yml
- openapi/benchling-containers-api-openapi.yml
- openapi/benchling-custom-entities-api-openapi.yml
- openapi/benchling-custom-notations-api-openapi.yml
- openapi/benchling-data-frames-api-openapi.yml
- openapi/benchling-datasets-api-openapi.yml
- openapi/benchling-dna-alignments-api-openapi.yml
- openapi/benchling-dna-oligos-api-openapi.yml
- openapi/benchling-dna-sequences-api-openapi.yml
- openapi/benchling-dropdowns-api-openapi.yml
- openapi/benchling-entities-api-openapi.yml
- openapi/benchling-entries-api-openapi.yml
- openapi/benchling-enzymes-api-openapi.yml
- openapi/benchling-events-api-openapi.yml
- openapi/benchling-exports-api-openapi.yml
- openapi/benchling-feature-libraries-api-openapi.yml
- openapi/benchling-files-api-openapi.yml
- openapi/benchling-folders-api-openapi.yml
- openapi/benchling-instrument-queries-api-openapi.yml
- openapi/benchling-inventory-api-openapi.yml
- openapi/benchling-lab-automation-api-openapi.yml
- openapi/benchling-label-templates-api-openapi.yml
- openapi/benchling-legacy-requests-api-openapi.yml
- openapi/benchling-legacy-workflows-api-openapi.yml
- openapi/benchling-legacy-workflows-deprecated-api-openapi.yml
- openapi/benchling-locations-api-openapi.yml
- openapi/benchling-mixtures-api-openapi.yml
- openapi/benchling-molecules-api-openapi.yml
- openapi/benchling-monomers-api-openapi.yml
- openapi/benchling-nucleotide-alignments-api-openapi.yml
- openapi/benchling-oligos-api-openapi.yml
- openapi/benchling-organizations-api-openapi.yml
- openapi/benchling-plates-api-openapi.yml
- openapi/benchling-printers-api-openapi.yml
- openapi/benchling-projects-api-openapi.yml
- openapi/benchling-registry-api-openapi.yml
- openapi/benchling-rna-oligos-api-openapi.yml
- openapi/benchling-rna-sequences-api-openapi.yml
- openapi/benchling-schemas-api-openapi.yml
- openapi/benchling-tasks-api-openapi.yml
- openapi/benchling-teams-api-openapi.yml
- openapi/benchling-users-api-openapi.yml
- openapi/benchling-v3-openapi.yaml
- openapi/benchling-warehouse-api-openapi.yml
- openapi/benchling-workflow-flowchart-config-versions-api-openapi.yml
- openapi/benchling-workflow-flowcharts-api-openapi.yml
- openapi/benchling-workflow-outputs-api-openapi.yml
- openapi/benchling-workflow-task-groups-api-openapi.yml
- openapi/benchling-workflow-tasks-api-openapi.yml
- name: oAuth
type: oauth2
flows:
- flow: clientCredentials
tokenUrl: /api/v2/token
scopes: 0
description: OAuth2 Client Credentials flow intended for service access
sources:
- openapi/benchling-aa-sequences-api-openapi.yml
- openapi/benchling-apps-api-openapi.yml
- openapi/benchling-assay-results-api-openapi.yml
- openapi/benchling-assay-runs-api-openapi.yml
- openapi/benchling-audit-api-openapi.yml
- openapi/benchling-authentication-api-openapi.yml
- openapi/benchling-blobs-api-openapi.yml
- openapi/benchling-boxes-api-openapi.yml
- openapi/benchling-codon-usage-tables-api-openapi.yml
- openapi/benchling-connect-api-openapi.yml
- openapi/benchling-containers-api-openapi.yml
- openapi/benchling-custom-entities-api-openapi.yml
- openapi/benchling-custom-notations-api-openapi.yml
- openapi/benchling-data-frames-api-openapi.yml
- openapi/benchling-datasets-api-openapi.yml
- openapi/benchling-dna-alignments-api-openapi.yml
- openapi/benchling-dna-oligos-api-openapi.yml
- openapi/benchling-dna-sequences-api-openapi.yml
- openapi/benchling-dropdowns-api-openapi.yml
- openapi/benchling-entities-api-openapi.yml
- openapi/benchling-entries-api-openapi.yml
- openapi/benchling-enzymes-api-openapi.yml
- openapi/benchling-events-api-openapi.yml
- openapi/benchling-exports-api-openapi.yml
- openapi/benchling-feature-libraries-api-openapi.yml
- openapi/benchling-files-api-openapi.yml
- openapi/benchling-folders-api-openapi.yml
- openapi/benchling-instrument-queries-api-openapi.yml
- openapi/benchling-inventory-api-openapi.yml
- openapi/benchling-lab-automation-api-openapi.yml
- openapi/benchling-label-templates-api-openapi.yml
- openapi/benchling-legacy-requests-api-openapi.yml
- openapi/benchling-legacy-workflows-api-openapi.yml
- openapi/benchling-legacy-workflows-deprecated-api-openapi.yml
- openapi/benchling-locations-api-openapi.yml
- openapi/benchling-mixtures-api-openapi.yml
- openapi/benchling-molecules-api-openapi.yml
- openapi/benchling-monomers-api-openapi.yml
- openapi/benchling-nucleotide-alignments-api-openapi.yml
- openapi/benchling-oligos-api-openapi.yml
- openapi/benchling-organizations-api-openapi.yml
- openapi/benchling-plates-api-openapi.yml
- openapi/benchling-printers-api-openapi.yml
- openapi/benchling-projects-api-openapi.yml
- openapi/benchling-registry-api-openapi.yml
- openapi/benchling-rna-oligos-api-openapi.yml
- openapi/benchling-rna-sequences-api-openapi.yml
- openapi/benchling-schemas-api-openapi.yml
- openapi/benchling-tasks-api-openapi.yml
- openapi/benchling-teams-api-openapi.yml
- openapi/benchling-users-api-openapi.yml
- openapi/benchling-v3-openapi.yaml
- openapi/benchling-warehouse-api-openapi.yml
- openapi/benchling-workflow-flowchart-config-versions-api-openapi.yml
- openapi/benchling-workflow-flowcharts-api-openapi.yml
- openapi/benchling-workflow-outputs-api-openapi.yml
- openapi/benchling-workflow-task-groups-api-openapi.yml
- openapi/benchling-workflow-tasks-api-openapi.yml
docs: https://docs.benchling.com/docs/authentication
documented_methods:
- name: Basic authentication (user API key)
scheme: http basic
openapi_scheme: basicApiKeyAuth
detail: API key as the HTTP Basic USERNAME with an EMPTY password — note the trailing colon in `curl
-u KEY:`. Failed auth returns 401. Keys are generated and rotated in Profile settings.
identity: acts as the user who owns the key
recommended_for: quick tests and one-off scripts
- name: OAuth 2.0 client credentials (Benchling Apps)
scheme: oauth2 clientCredentials
openapi_scheme: oAuth
token_url: https://{tenant}.benchling.com/api/v2/token
exchange_auth: basicClientIdSecretAuth (client_id / client_secret) or form-encoded body
detail: 'POST client_id + client_secret + grant_type=client_credentials to /token, receive a short-lived
access_token, send Authorization: Bearer, re-fetch on expiry.'
identity: acts as the app (a service principal)
recommended_for: dedicated integrations and automation — the recommended default
- name: OpenID Connect id token
scheme: bearer id_token
openapi_scheme: null
detail: Enterprise only, and NOT declared in the OpenAPI. A trusted IdP issues an id token containing
an `email` claim; Benchling verifies the signature against the customer's own /.well-known/openid-configuration
and authenticates as the matching user, who must already exist in the tenant. Confirmed working with
Okta and Azure AD / Entra ID. Requires setup through support@benchling.com.
identity: acts as any user resolvable in the IdP
recommended_for: integrations that must act as many different users
spec_gap: The OpenAPI declares only the two HTTP Basic schemes and the OAuth2 client-credentials flow.
The OIDC id-token path is documented but absent from both specs, so a client generated purely from the
contract cannot discover it.
secrets_handling:
api_key_rotation: Profile settings
client_secret_rotation: Apps page in the Developer Console
guidance: Benchling advises storing credentials in a password manager or secrets store and using environment
variables rather than embedding them in scripts.
warehouse: The Benchling Data Warehouse does not use any of these methods — it is a direct Postgres connection
with its own credentials. See https://docs.benchling.com/docs/getting-started.
scopes: scopes/benchling-scopes.yml