Overview of the SSO flow
With the .NET Integration Kit, PingFederate exchanges user attributes with your .NET 8 application through an OpenToken.
The following figure shows a basic identity provider (IdP)-initiated single sign-on (SSO) scenario in which PingFederate federation servers using the .NET Integration Kit exist on both sides of the identity federation:

Description
-
A user initiates an SSO transaction.
-
The IdP application passes user attributes to the .NET 8 OpenToken Agent, which encrypts the data internally and generates an OpenToken.
-
A request containing the OpenToken is redirected to the PingFederate IdP server.
-
The PingFederate IdP server invokes the OpenToken IdP Adapter, which retrieves and decrypts the OpenToken, parses the user attributes, and uses them to generate a SAML assertion.
-
The SAML assertion is sent to the SP site.
-
The PingFederate SP server parses the SAML assertion and passes the user attributes to the OpenToken SP Adapter. The adapter encrypts the data internally and generates an OpenToken.
-
A request containing the OpenToken is redirected to the SP application.
-
The .NET 8 OpenToken Agent decrypts and parses the OpenToken, making the user attributes available to the SP Application.