Connector · Enterprise identity platform

Ping Identity, in front of your sign-in.

How our authentication module uses Ping Identity: PingOne or PingFederate as the identity provider, the sign-in journeys Ping runs, and how we connect it.

Website
pingidentity.com
Modules
Authentication
SDKs
Web, iOS, Android
Contract
We help you get it

Who Ping Identity is

Ping Identity is an identity security company founded in 2002 and based in Denver, owned by Thoma Bravo since 2022. ForgeRock was combined into it in 2023, and its platform covers single sign-on, multi-factor and passwordless authentication, orchestration and threat protection, for customers, business partners and staff.

Its products include PingOne, a cloud service, and PingFederate, a federation server companies run themselves, and both speak OpenID Connect and SAML. Large organisations with many apps and directories rely on it, which is why it is one of the identity providers our authentication module connects to.

What it does in your platform

  • Authentication

    Acts as the identity provider behind the module, through PingOne in the cloud or PingFederate on your own servers, over OpenID Connect or SAML. Ping runs the sign-in journey, from multi-factor to risk checks; the module keeps the sessions, trusted devices and the second factor on payments.

How the connection works

The module connects to PingOne or PingFederate as an OpenID Connect or SAML application. On PingOne, webhooks push sign-in events to the platform as they happen.

  1. The app hands over

    When a customer signs in, the app sends them to your Ping environment through a standard OpenID Connect request.

  2. Ping runs the journey

    A PingOne DaVinci flow or a PingFederate policy decides the steps: a password or passwordless sign-in, multi-factor, and a risk score from PingOne Protect where you use it.

  3. Tokens come back

    Ping returns signed tokens to the module, which checks them and opens a session tied to the customer's device.

  4. A payment asks for more

    Confirming a transfer or a card payment asks for the second factor strong customer authentication requires, on top of the Ping session.

  5. Events reach the platform

    PingOne webhooks push sign-in events to the platform as they happen, and they show up in the backoffice next to the customer.

Next to other providers

Ping can sign in your customers while staff use your company directory, or run both if your organisation already uses it. PingFederate can also bridge several identity providers into one connection for the module.

Because the module speaks OpenID Connect and SAML rather than Ping's own interfaces, moving to Ping or away from it later is a configuration change, and your apps stay the same.

When Ping Identity fits best

A strong fit when

  • Your organisation already runs PingOne or PingFederate.
  • You want sign-in journeys designed without code, with risk checks built in.
  • You need identity in the cloud and on your own servers, from one vendor.

Also worth a look

  • Okta or Microsoft Entra ID, when your staff directory already lives there.
  • Auth0 or AWS Cognito, when customer sign-in is all you need from an identity provider.

How we get you live

  • The contract

    We help you get your Ping Identity account and contract in place, or connect to the Ping environment you already run.

  • The journeys

    We set up the sign-in journeys with you in DaVinci or PingFederate: the steps, the multi-factor rules and where risk checks apply.

  • The keys

    Client secrets and webhook settings go into your platform's secrets and nowhere else.

  • A full test run

    We test sign-in, a risky attempt and a confirmed payment in a separate Ping test environment before your first real customer.

Questions

Asked about this connector.

How do we get started with Ping Identity?

Talk to us. We help you get the Ping Identity contract in place, or connect to the environment you already run, set up the sign-in journeys with you and test them end to end before your first real customer.

Can we run PingFederate on our own servers?

Yes. PingFederate is a federation server you run yourselves, and the module connects to it over OpenID Connect or SAML, the same way it connects to PingOne in the cloud.

Is ForgeRock part of Ping Identity now?

Yes. ForgeRock was combined into Ping Identity in 2023, and its technology is now part of the Ping platform.

Do our apps need Ping's SDKs?

Not for a sign-in that runs on Ping's hosted pages over OpenID Connect. When a journey needs native screens, Ping offers SDKs for Android, iOS and JavaScript.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?