Benchling · Authentication Profile

Benchling Authentication

Authentication

Benchling secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

Life SciencesBiotechR&DMolecular BiologyLaboratory Information ManagementElectronic Lab NotebookAssay ManagementInventory ManagementSequence ManagementExperiment WorkflowsRESTWebhook
Methods: http, oauth2 Schemes: 2 OAuth flows: clientCredentials API key in:

Security Schemes

basicApiKeyAuth http
scheme: basic
oAuth oauth2
· flows: clientCredentials

Source

Authentication Profile

Raw ↑
generated: '2026-08-15'
method: searched
source: openapi/benchling-v3-openapi.yaml + openapi/*.yml securitySchemes, enriched from https://docs.benchling.com/docs/authentication
  and https://docs.benchling.com/docs/getting-started-benchling-apps, read 2026-08-15.
summary:
  types:
  - http
  - oauth2
  oauth2_flows:
  - clientCredentials
schemes:
- name: basicApiKeyAuth
  type: http
  scheme: basic
  description: Use issued API key for standard access to the API
  sources:
  - openapi/benchling-aa-sequences-api-openapi.yml
  - openapi/benchling-apps-api-openapi.yml
  - openapi/benchling-assay-results-api-openapi.yml
  - openapi/benchling-assay-runs-api-openapi.yml
  - openapi/benchling-audit-api-openapi.yml
  - openapi/benchling-authentication-api-openapi.yml
  - openapi/benchling-blobs-api-openapi.yml
  - openapi/benchling-boxes-api-openapi.yml
  - openapi/benchling-codon-usage-tables-api-openapi.yml
  - openapi/benchling-connect-api-openapi.yml
  - openapi/benchling-containers-api-openapi.yml
  - openapi/benchling-custom-entities-api-openapi.yml
  - openapi/benchling-custom-notations-api-openapi.yml
  - openapi/benchling-data-frames-api-openapi.yml
  - openapi/benchling-datasets-api-openapi.yml
  - openapi/benchling-dna-alignments-api-openapi.yml
  - openapi/benchling-dna-oligos-api-openapi.yml
  - openapi/benchling-dna-sequences-api-openapi.yml
  - openapi/benchling-dropdowns-api-openapi.yml
  - openapi/benchling-entities-api-openapi.yml
  - openapi/benchling-entries-api-openapi.yml
  - openapi/benchling-enzymes-api-openapi.yml
  - openapi/benchling-events-api-openapi.yml
  - openapi/benchling-exports-api-openapi.yml
  - openapi/benchling-feature-libraries-api-openapi.yml
  - openapi/benchling-files-api-openapi.yml
  - openapi/benchling-folders-api-openapi.yml
  - openapi/benchling-instrument-queries-api-openapi.yml
  - openapi/benchling-inventory-api-openapi.yml
  - openapi/benchling-lab-automation-api-openapi.yml
  - openapi/benchling-label-templates-api-openapi.yml
  - openapi/benchling-legacy-requests-api-openapi.yml
  - openapi/benchling-legacy-workflows-api-openapi.yml
  - openapi/benchling-legacy-workflows-deprecated-api-openapi.yml
  - openapi/benchling-locations-api-openapi.yml
  - openapi/benchling-mixtures-api-openapi.yml
  - openapi/benchling-molecules-api-openapi.yml
  - openapi/benchling-monomers-api-openapi.yml
  - openapi/benchling-nucleotide-alignments-api-openapi.yml
  - openapi/benchling-oligos-api-openapi.yml
  - openapi/benchling-organizations-api-openapi.yml
  - openapi/benchling-plates-api-openapi.yml
  - openapi/benchling-printers-api-openapi.yml
  - openapi/benchling-projects-api-openapi.yml
  - openapi/benchling-registry-api-openapi.yml
  - openapi/benchling-rna-oligos-api-openapi.yml
  - openapi/benchling-rna-sequences-api-openapi.yml
  - openapi/benchling-schemas-api-openapi.yml
  - openapi/benchling-tasks-api-openapi.yml
  - openapi/benchling-teams-api-openapi.yml
  - openapi/benchling-users-api-openapi.yml
  - openapi/benchling-v3-openapi.yaml
  - openapi/benchling-warehouse-api-openapi.yml
  - openapi/benchling-workflow-flowchart-config-versions-api-openapi.yml
  - openapi/benchling-workflow-flowcharts-api-openapi.yml
  - openapi/benchling-workflow-outputs-api-openapi.yml
  - openapi/benchling-workflow-task-groups-api-openapi.yml
  - openapi/benchling-workflow-tasks-api-openapi.yml
- name: oAuth
  type: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: /api/v2/token
    scopes: 0
  description: OAuth2 Client Credentials flow intended for service access
  sources:
  - openapi/benchling-aa-sequences-api-openapi.yml
  - openapi/benchling-apps-api-openapi.yml
  - openapi/benchling-assay-results-api-openapi.yml
  - openapi/benchling-assay-runs-api-openapi.yml
  - openapi/benchling-audit-api-openapi.yml
  - openapi/benchling-authentication-api-openapi.yml
  - openapi/benchling-blobs-api-openapi.yml
  - openapi/benchling-boxes-api-openapi.yml
  - openapi/benchling-codon-usage-tables-api-openapi.yml
  - openapi/benchling-connect-api-openapi.yml
  - openapi/benchling-containers-api-openapi.yml
  - openapi/benchling-custom-entities-api-openapi.yml
  - openapi/benchling-custom-notations-api-openapi.yml
  - openapi/benchling-data-frames-api-openapi.yml
  - openapi/benchling-datasets-api-openapi.yml
  - openapi/benchling-dna-alignments-api-openapi.yml
  - openapi/benchling-dna-oligos-api-openapi.yml
  - openapi/benchling-dna-sequences-api-openapi.yml
  - openapi/benchling-dropdowns-api-openapi.yml
  - openapi/benchling-entities-api-openapi.yml
  - openapi/benchling-entries-api-openapi.yml
  - openapi/benchling-enzymes-api-openapi.yml
  - openapi/benchling-events-api-openapi.yml
  - openapi/benchling-exports-api-openapi.yml
  - openapi/benchling-feature-libraries-api-openapi.yml
  - openapi/benchling-files-api-openapi.yml
  - openapi/benchling-folders-api-openapi.yml
  - openapi/benchling-instrument-queries-api-openapi.yml
  - openapi/benchling-inventory-api-openapi.yml
  - openapi/benchling-lab-automation-api-openapi.yml
  - openapi/benchling-label-templates-api-openapi.yml
  - openapi/benchling-legacy-requests-api-openapi.yml
  - openapi/benchling-legacy-workflows-api-openapi.yml
  - openapi/benchling-legacy-workflows-deprecated-api-openapi.yml
  - openapi/benchling-locations-api-openapi.yml
  - openapi/benchling-mixtures-api-openapi.yml
  - openapi/benchling-molecules-api-openapi.yml
  - openapi/benchling-monomers-api-openapi.yml
  - openapi/benchling-nucleotide-alignments-api-openapi.yml
  - openapi/benchling-oligos-api-openapi.yml
  - openapi/benchling-organizations-api-openapi.yml
  - openapi/benchling-plates-api-openapi.yml
  - openapi/benchling-printers-api-openapi.yml
  - openapi/benchling-projects-api-openapi.yml
  - openapi/benchling-registry-api-openapi.yml
  - openapi/benchling-rna-oligos-api-openapi.yml
  - openapi/benchling-rna-sequences-api-openapi.yml
  - openapi/benchling-schemas-api-openapi.yml
  - openapi/benchling-tasks-api-openapi.yml
  - openapi/benchling-teams-api-openapi.yml
  - openapi/benchling-users-api-openapi.yml
  - openapi/benchling-v3-openapi.yaml
  - openapi/benchling-warehouse-api-openapi.yml
  - openapi/benchling-workflow-flowchart-config-versions-api-openapi.yml
  - openapi/benchling-workflow-flowcharts-api-openapi.yml
  - openapi/benchling-workflow-outputs-api-openapi.yml
  - openapi/benchling-workflow-task-groups-api-openapi.yml
  - openapi/benchling-workflow-tasks-api-openapi.yml
docs: https://docs.benchling.com/docs/authentication
documented_methods:
- name: Basic authentication (user API key)
  scheme: http basic
  openapi_scheme: basicApiKeyAuth
  detail: API key as the HTTP Basic USERNAME with an EMPTY password — note the trailing colon in `curl
    -u KEY:`. Failed auth returns 401. Keys are generated and rotated in Profile settings.
  identity: acts as the user who owns the key
  recommended_for: quick tests and one-off scripts
- name: OAuth 2.0 client credentials (Benchling Apps)
  scheme: oauth2 clientCredentials
  openapi_scheme: oAuth
  token_url: https://{tenant}.benchling.com/api/v2/token
  exchange_auth: basicClientIdSecretAuth (client_id / client_secret) or form-encoded body
  detail: 'POST client_id + client_secret + grant_type=client_credentials to /token, receive a short-lived
    access_token, send Authorization: Bearer, re-fetch on expiry.'
  identity: acts as the app (a service principal)
  recommended_for: dedicated integrations and automation — the recommended default
- name: OpenID Connect id token
  scheme: bearer id_token
  openapi_scheme: null
  detail: Enterprise only, and NOT declared in the OpenAPI. A trusted IdP issues an id token containing
    an `email` claim; Benchling verifies the signature against the customer's own /.well-known/openid-configuration
    and authenticates as the matching user, who must already exist in the tenant. Confirmed working with
    Okta and Azure AD / Entra ID. Requires setup through support@benchling.com.
  identity: acts as any user resolvable in the IdP
  recommended_for: integrations that must act as many different users
spec_gap: The OpenAPI declares only the two HTTP Basic schemes and the OAuth2 client-credentials flow.
  The OIDC id-token path is documented but absent from both specs, so a client generated purely from the
  contract cannot discover it.
secrets_handling:
  api_key_rotation: Profile settings
  client_secret_rotation: Apps page in the Developer Console
  guidance: Benchling advises storing credentials in a password manager or secrets store and using environment
    variables rather than embedding them in scripts.
warehouse: The Benchling Data Warehouse does not use any of these methods — it is a direct Postgres connection
  with its own credentials. See https://docs.benchling.com/docs/getting-started.
scopes: scopes/benchling-scopes.yml