---
title: Configuring PingFederate to extract token attributes
description: Configure PingFederate for the PingIntelligence policy to be able to extract the username from the incoming token.
component: pingintelligence
version: 5.2
page_id: pingintelligence:pingintelligence_integrations:pingintelligence_configure_pf
canonical_url: https://docs.pingidentity.com/pingintelligence/5.2/pingintelligence_integrations/pingintelligence_configure_pf.html
revdate: April 3, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configuring PingFederate to extract token attributes

Configure PingFederate for the PingIntelligence policy to be able to extract the username from the incoming token.

## About this task

To configure PingFederate to extract token attributes:

## Steps

1. While configuring **Access Token Management** in PingFederate, add all the attributes that should be exposed for the token. PingFederate provides these attribute values to PingAccess for OAuth tokens.

2. Click **Access Token Attribute Contract** under **Create Access Token Management Instance** and add the required attributes. Make sure to at least add **Username**.

   ![A screen capture of the Access Token Management > Create Access Token Management Instance page on the Access Token Attribute Contract tab.](../_images/tfc1564009274970.png)

3. After adding the required attributes, configure the attribute sources:

   1. Click **Access Token Mapping**.

   2. Select the relevant **Context**.

   3. Click **Contract Fulfilment**.

   ![A screen capture of the Access Token Attribute Mapping \\| Access Token Mapping page on the Contract Fulfillment tab.](../_images/xge1564009275788.png)
