---
title: PingOne Integration Kit
description: The PingOne Integration Kit adds PingOne datastore, password credential validator, and provisioning connector options to PingFederate. These options allow you to integrate PingFederate with PingOne and services such as PingOne MFA in a variety of ways.
component: pingone
page_id: pingone::pf_p1_ik
canonical_url: https://docs.pingidentity.com/integrations/pingone/pf_p1_ik.html
revdate: November 20, 2025
section_ids:
  components: Components
  intended-audience: Intended audience
  system-requirements: System requirements
---

# PingOne Integration Kit

The PingOne Integration Kit adds PingOne datastore, password credential validator, and provisioning connector options to PingFederate. These options allow you to integrate PingFederate with PingOne and services such as PingOne MFA in a variety of ways.

## Components

You can use these components individually or together.

* Datastore and password credential validator

  * The datastore allows PingFederate to retrieve user attributes from PingOne.

  * The password credential validator allows PingFederate to validate user credentials against the PingOne datastore during sign-on.

* Provisioning connector

  * Allows the PingFederate provisioning engine to manage users and groups in PingOne.

  * Allows PingFederate to manage users' SMS, email, and voice devices for PingOne MFA.

  * Allows PingFederate to create custom attributes.

The user guide also provides instructions for creating an OpenID Connect integration with PingOne.

## Intended audience

This document is intended for PingFederate administrators.

If you need help during the setup process, learn more in the following resources:

* [Introduction to PingOne](https://docs.pingidentity.com/pingone/introduction_to_pingone/p1_introduction.html) in the PingOne documentation

* [Strong Authentication (MFA)](https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_strong_authentication_start.html) in the PingOne MFA documentation

* The following sections of the PingFederate documentation:

  * [Datastores](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_datastores.html)

  * [Password credential validators](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_passwordcredentialvalidatortasklet_passwordcredentialvalidatormgmtstate.html)

  * [SP connection management](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_sp_connect_management.html)

  * [Configuring outbound provisioning](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_saasprovisioningstate.html)

  * [Configuring outbound provisioning settings](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_protocolsettingstasklet_saasglobalprovisioningsettingsstate.html)

## System requirements

* PingFederate 11.3 or later

* To allow PingFederate to make outbound HTTPS connections, you might need to allow the following hostnames in your firewall:

  * https\://api.pingone.com, https\://api.pingone.asia, or https\://api.pingone.eu

  * https\://auth.pingone.com, https\://auth.pingone.asia, or https\://auth.pingone.eu
