Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

SeamlessAccess: How Federated Single Sign-On Works for Institutional Access

SeamlessAccess is a not-for-profit, NISO/GEANT/Internet2/STM-governed initiative for federated single sign-on to subscribed scholarly content. This guide covers how SAML-based authentication and the WAYF institution-selection process work, and how SeamlessAccess differs from and complements GetFTR.

SeamlessAccess is a not-for-profit, collaborative initiative that lets a researcher sign in to publisher platforms, discovery tools, and other scholarly services using the same institutional credentials they already use on campus — a university or library login — instead of a separate username and password for every subscribed resource. It is built on federated identity management, using the SAML (Security Assertion Markup Language) standard that many campuses already rely on for other single sign-on needs, and it is governed jointly by NISO, GÉANT, Internet2, and the International Association of Scientific, Technical, and Medical Publishers (STM). This guide explains what SeamlessAccess is, where it came from, how federated SAML authentication and the “Where Are You From” (WAYF) institution-selection process actually work, and how it differs from and complements GetFTR, the separate publisher service that checks whether a reader is entitled to a specific article.

What SeamlessAccess is and who runs it

SeamlessAccess describes itself as designed to foster a more streamlined online access experience when researchers use scholarly collaboration tools, subscribed information resources, and shared research infrastructure. It does not host content and it is not a publisher service in the way GetFTR is — it is infrastructure that sits between a researcher’s institutional identity and the many separate platforms (publisher sites, library systems, research tools) that need to recognize that identity to grant access.

The initiative is governed by four organizations, each bringing a different constituency: NISO (the U.S. standards body for library and publishing metadata and interoperability), GÉANT (the pan-European research and education networking organization that operates identity federations across national research networks), Internet2 (the U.S. research-and-education network that operates the InCommon identity federation), and STM (the international trade association for academic and professional publishers). That mix — standards, network, and publisher representation together — is a deliberate contrast with GetFTR, which is built and run by publishers on their own; see the comparison section below for why that governance difference matters in practice.

Where SeamlessAccess came from: the RA21 initiative

SeamlessAccess grew directly out of RA21 (Resource Access for the 21st Century), a joint STM and NISO project launched in 2016 to address a long-standing problem: most institutional access to subscribed scholarly content was, and in many cases still is, recognized by IP address — a publisher’s system treats any device connecting from a university’s registered network range as an authorized user. That model works on campus but breaks down constantly off campus, on VPNs, at partner institutions, and in an increasingly remote and hybrid research environment, and it has no good answer for confirming a specific person’s institutional affiliation rather than just their network location.

Over roughly three years, RA21 gathered input from around sixty organizations across the publishing, library, higher-education-IT, and identity-federation communities to explore alternatives. The project concluded on June 30, 2019, with NISO’s publication of RP-27-2019, the Recommended Practice for Improved Access to Institutionally-Provided Information Resources, whose central recommendation was to establish a permanent, operational service to carry the work forward. That service, SeamlessAccess, launched in July 2019 under the joint NISO/GÉANT/Internet2/STM governance structure described above.

How federated SAML authentication actually works

SeamlessAccess does not issue its own logins or store researcher passwords. It relies on federated identity management, a model in which a researcher’s home institution remains the sole authority on who that person is, and other services trust the institution’s confirmation rather than maintaining their own separate account for that person. The mechanics follow the SAML standard, the same open standard behind campus tools like Shibboleth-based single sign-on:

  • The publisher or platform a researcher is trying to reach acts as the Service Provider (SP).
  • The researcher’s home institution operates an Identity Provider (IdP) — the system that actually authenticates the person, typically the same login used for email, the library catalog, or other campus systems.
  • When a researcher tries to access a subscribed resource, the Service Provider redirects them to their institution’s Identity Provider to log in (or recognizes an existing campus session). The IdP authenticates the researcher locally — the publisher never sees or handles the researcher’s actual campus password — and then sends back a SAML assertion confirming the researcher’s affiliation and any other attributes the institution has agreed to release (such as an eligible-user status), without necessarily disclosing the researcher’s identity beyond what’s needed.
  • The Service Provider uses that assertion to grant access, the same way it would recognize an on-campus IP address, except now the recognition follows the person rather than a network location — enabling seamless off-campus, VPN-free access to the same subscribed content a researcher could reach on campus.

National and regional research-and-education identity federations — InCommon in the United States (operated by Internet2) and the national federations that interconnect through GÉANT’s eduGAIN service in Europe and beyond — are what make this trust relationship scale: a publisher only has to trust a federation, not negotiate a separate technical relationship with every individual university.

The “Where Are You From” (WAYF) problem SeamlessAccess solves

Federated authentication introduces its own usability problem, commonly called “Where Are You From” or WAYF: before a Service Provider can redirect a researcher to the right Identity Provider, it has to know which institution that researcher belongs to. Historically that meant presenting the researcher with a long, often alphabetically sorted list of thousands of institutions to search through and select from — on every single publisher site, every time, since institution names are frequently ambiguous or duplicated across the list (multiple campuses sharing a similar name, for example).

SeamlessAccess’s core practical function is standardizing and smoothing this WAYF step. It provides a common institution-finder interface that participating publishers and platforms can adopt instead of building their own, and it stores a researcher’s selected institution locally in their browser so that trusted participating services can recognize the choice on subsequent visits — meaning a researcher generally only has to search for and select their institution once, rather than repeating the search on every publisher’s site. That single, comparatively small usability fix is the specific friction SeamlessAccess targets: not the strength of the underlying SAML security model, which was already well established in campus IT before RA21 began, but the repeated, confusing institution-selection step that made federated login feel worse than a simple password to many researchers and librarians.

SeamlessAccess vs. GetFTR: authentication vs. entitlement checking

SeamlessAccess and GetFTR are frequently mentioned together, launched within roughly the same window (2019–2020), and are often confused, but they solve two different problems in the same access chain, and CASRAI covers both because research offices and librarians need to know which one to point a confused researcher toward:

  • SeamlessAccess answers “who is this reader?” — it handles authentication, letting a researcher sign in with their institutional credentials via federated SSO so that a publisher or platform can recognize their institutional affiliation in the first place.
  • GetFTR answers “does this reader’s institution have rights to this specific article, right now?” — it checks entitlement at the point of discovery, before a researcher even clicks through to a publisher’s site, using either a SAML institutional identifier or an IP address as its signal.

The two are designed to complement rather than compete with each other: GetFTR’s entitlement check can use the same SAML institutional identifier that SeamlessAccess-style federated authentication establishes, so a researcher who has already been recognized via federated SSO generally gets a more accurate GetFTR entitlement result than one relying on IP address alone. The governance difference matters here too — SeamlessAccess’s multi-stakeholder coalition (standards body, two research-and-education networks, and the publisher trade association together) sits in contrast to GetFTR’s publisher-only governance, a distinction that drew library-sector commentary when both services launched. In short: a researcher gets the smoothest discovery-to-full-text experience when both are in play — SeamlessAccess establishing who they are, GetFTR confirming what they’re entitled to read.

Why this matters for research administration and off-campus access

Off-campus and remote access to subscribed content is a routine, recurring friction point: a researcher working from home, traveling, or affiliated with a partner institution needs the same access to licensed journals and databases they’d have on campus, without a VPN client, a separate proxy login, or a support ticket to the library. Federated authentication through SeamlessAccess addresses this directly by making a researcher’s institutional identity itself the access credential, portable to wherever they’re actually working, rather than tying access to a specific network location. For research administrators and librarians, understanding the SAML/IdP relationship also matters operationally: when a researcher reports being unable to access a subscribed resource off campus, the fault more often lies in how the institution’s Identity Provider or the publisher’s Service Provider configuration is set up (attribute release policies, IdP registration with the relevant federation) than with SeamlessAccess itself, which does not control either endpoint.

SeamlessAccess is one part of a broader access-infrastructure stack alongside library link resolvers, institutional repositories, and entitlement-checking services like GetFTR — each solving a distinct piece of getting a legitimate reader to the content their institution has already licensed or made available.

Frequently asked questions

Is SeamlessAccess a publisher or a login provider?

Neither, in the direct sense. SeamlessAccess is infrastructure and a shared institution-finder/WAYF experience; the actual authentication is performed by a researcher’s own institution (the Identity Provider), and access decisions are made by the publisher or platform (the Service Provider). SeamlessAccess does not store researcher passwords.

Does my institution need to do anything for SeamlessAccess to work?

Yes. A researcher’s institution needs an operational SAML Identity Provider registered with a research-and-education identity federation (such as InCommon in the U.S. or a national federation connected via GÉANT’s eduGAIN), and the publisher or platform needs to support SAML-based federated login as a Service Provider. Most research universities and many other institutions already have this in place, since it’s the same infrastructure used for campus single sign-on more broadly.

Is SeamlessAccess the same as Shibboleth?

No, though they’re closely related. Shibboleth is one widely used open-source software implementation of SAML-based federated identity, commonly deployed by institutions as their Identity Provider. SeamlessAccess is a separate, higher-level initiative focused on standardizing the researcher-facing sign-in and institution-selection experience across publishers and platforms that use SAML (including but not limited to those using Shibboleth specifically).

Is SeamlessAccess the same as GetFTR?

No. SeamlessAccess handles authentication — confirming who a researcher is and which institution they belong to. GetFTR handles entitlement checking — confirming whether that institution has rights to a specific article. They’re designed to work together, not to replace each other; see CASRAI’s GetFTR guide for the entitlement-checking side.

Is SeamlessAccess free to use?

Yes, for researchers and institutions. SeamlessAccess operates as a not-for-profit initiative funded by its governing organizations rather than charging researchers directly for the sign-in experience.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →