---
title: Configuring user-session creation
description: You must create and configure user sessions when configuring service provider (SP) browser single sign-on (SSO).
component: pingfederate
version: 13.1
page_id: pingfederate:administrators_reference_guide:help_idpbrowserssotasklet_usersessioncreationstate
canonical_url: https://docs.pingidentity.com/pingfederate/13.1/administrators_reference_guide/help_idpbrowserssotasklet_usersessioncreationstate.html
llms_txt: https://docs.pingidentity.com/pingfederate/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: July 5, 2022
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configuring user-session creation

You must create and configure user sessions when configuring service provider (SP) browser single sign-on (SSO).

## About this task

As an SP, you must specify how PingFederate uses information sent from the IdP in SSO tokens to create user sessions for enabling access to protected resources at your site.

If you are a federation hub, bridging an identity provider to one or more service providers, you can associate one or more authentication policy contracts to the IdP connection. For more information, see [Federation hub use cases](../introduction_to_pingfederate/pf_fed_hub_use_case.html).

The configuration involves choosing an identity-mapping method, establishing an attribute contract as needed, and optionally mapping one or more SP adapter instances, authentication policy contracts, or both.

## Steps

* On the **User-Session Creation** tab, click **Configure User-Session Creation**.
