Who Ping Identity is
Ping Identity is an identity security company founded in 2002 and based in Denver, owned by Thoma Bravo since 2022. ForgeRock was combined into it in 2023, and its platform covers single sign-on, multi-factor and passwordless authentication, orchestration and threat protection, for customers, business partners and staff.
Its products include PingOne, a cloud service, and PingFederate, a federation server companies run themselves, and both speak OpenID Connect and SAML. Large organisations with many apps and directories rely on it, which is why it is one of the identity providers our authentication module connects to.
What it does in your platform
Authentication
Acts as the identity provider behind the module, through PingOne in the cloud or PingFederate on your own servers, over OpenID Connect or SAML. Ping runs the sign-in journey, from multi-factor to risk checks; the module keeps the sessions, trusted devices and the second factor on payments.
How the connection works
The module connects to PingOne or PingFederate as an OpenID Connect or SAML application. On PingOne, webhooks push sign-in events to the platform as they happen.
The app hands over
When a customer signs in, the app sends them to your Ping environment through a standard OpenID Connect request.
Ping runs the journey
A PingOne DaVinci flow or a PingFederate policy decides the steps: a password or passwordless sign-in, multi-factor, and a risk score from PingOne Protect where you use it.
Tokens come back
Ping returns signed tokens to the module, which checks them and opens a session tied to the customer's device.
A payment asks for more
Confirming a transfer or a card payment asks for the second factor strong customer authentication requires, on top of the Ping session.
Events reach the platform
PingOne webhooks push sign-in events to the platform as they happen, and they show up in the backoffice next to the customer.
Next to other providers
Ping can sign in your customers while staff use your company directory, or run both if your organisation already uses it. PingFederate can also bridge several identity providers into one connection for the module.
Because the module speaks OpenID Connect and SAML rather than Ping's own interfaces, moving to Ping or away from it later is a configuration change, and your apps stay the same.
When Ping Identity fits best
A strong fit when
- Your organisation already runs PingOne or PingFederate.
- You want sign-in journeys designed without code, with risk checks built in.
- You need identity in the cloud and on your own servers, from one vendor.
Also worth a look
- Okta or Microsoft Entra ID, when your staff directory already lives there.
- Auth0 or AWS Cognito, when customer sign-in is all you need from an identity provider.
How we get you live
The contract
We help you get your Ping Identity account and contract in place, or connect to the Ping environment you already run.
The journeys
We set up the sign-in journeys with you in DaVinci or PingFederate: the steps, the multi-factor rules and where risk checks apply.
The keys
Client secrets and webhook settings go into your platform's secrets and nowhere else.
A full test run
We test sign-in, a risky attempt and a confirmed payment in a separate Ping test environment before your first real customer.
