---
title: PingFederateService
description: Configure a PingFederateService to enable PingGateway filters to reference PingFederate through a service endpoint
component: pinggateway
version: 2026
page_id: pinggateway:reference:PingFederateService
canonical_url: https://docs.pingidentity.com/pinggateway/2026/reference/PingFederateService.html
llms_txt: https://docs.pingidentity.com/pinggateway/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-09-14T13:45:25Z
section_ids:
  usage: Usage
  properties: Properties
  example: Example
---

# PingFederateService

Holds information about a PingFederate server. Filters using the server reference a PingFederateService.

## Usage

```json
{
  "name": string,
  "type": "PingFederateService",
  "config": {
    "serviceUrl": configuration expression<url>,
    "endpointHandler": Handler reference,
    "jwkset": {
      "cacheTimeout": configuration expression<duration>,
      "cacheMissTimeout": configuration expression<duration>
    }
  }
}
```

## Properties

* `"serviceUrl"`: *configuration expression<[url](preface.html#definition-url)>, required*

  The PingFederate root service URL.

  Example: `https://pingfed.example.com:9031`.

* `"endpointHandler"`: *Handler [reference](preface.html#definition-reference), optional*

  The [handler](Handlers.html) that makes requests to the service URL.

  Make sure this handler can access PingFederate endpoints for the services it makes requests to.

  Default: [ForgeRockClientHandler](ForgeRockClientHandler.html) as defined in the heap

* `"jwkset"`: *[object](preface.html#definition-object), optional*

  The configuration for retrieving the PingFederate JSON Web Key (JWK) set. PingGateway derives the JWK set endpoint by appending the path `/pf/JWKS` to the `"serviceUrl"`.

  The PingFederateService fetches only JWKs with a `sig` purpose to prevent selecting the wrong key when verifying a key signature. The PingFederate server must set `sig` on its JWK set signing keys.

  * `"cacheTimeout"`: *configuration expression<[duration](preface.html#definition-duration)>, optional*

    Delay before reloading the JWK set cache to avoid doing so too often.

    Default: 2 minutes

  * `"cacheMissTimeout"`: *configuration expression<[duration](preface.html#definition-duration)>, optional*

    The delay before reloading the cache after a cache miss. A cache miss arises, for example, when the JWK key ID is unknown. This avoids hammering the endpoint when a specific key isn't yet cached.

    Default: 2 minutes

## Example

The following example shows a PingFederateService using the default endpoint handler and cache settings:

```json
{
    "name": "PingFederateService-1",
    "type": "PingFederateService",
    "config": {
        "serviceEndpoint": "https://pingfed.example.com:9031"
    }
}
```
