SCIM Provisioner

PingFederate SSO details for the service provider

When enabling single sign-on (SSO) in the target service, you will require some or all of the following information from PingFederate.

Metadata file

Some target services allow you to import a Security Assertion Markup Language (SAML) metadata file that contains some of the following information. Learn more about exporting your metadata file in Metadata export in the PingFederate documentation.

SAML endpoint

The PingFederate SAML endpoint is:

https://<pf_hostname>:<pf_port>/idp/SSO.saml2

Identity provider issuer

This is SAML 2.0 Entity ID from PingFederate, which can be found on the Server Settings page. Learn more in Specifying federation information.

To override SAML 2.0 Entity ID on the Server Settings page for your SP Connection, go to the General Info page to add a Virtual Server ID. This value will be sent as the SAML Issuer URL.

Signing certificate

This is the public signing certificate that PingFederate uses to sign the SAML assertion. Learn more about exporting your certificate in Managing digital signing certificates and decryption keys.