PingOne

PingOne Remote MCP Server (early access)

The PingOne Remote MCP Server is now available for early access (EA).

The PingOne Remote MCP Server lets artificial intelligence (AI) clients connect to PingOne through a single remote Model Context Protocol (MCP) endpoint. Because the server is remote, you don’t need to install, configure, or run a local MCP server.

After configuring a supported client, administrators authenticate through PingOne with OAuth. They can then securely use MCP tools to administer the PingOne platform.

All MCP tools adhere to the PingOne roles and permissions model. Administrators can only access and use tools supported by their existing roles.

MCP Server settings

To support the release of the PingOne Remote MCP Server, we’ve added a new MCP Server page in the Settings section of the PingOne admin console. Enable or disable the PingOne Remote MCP Server for the environment on this page (MCP server access is disabled by default).

A screenshot of the MCP Server settings page in the PingOne admin console.

To enable the PingOne Remote MCP Server, click Enable MCP Access.

You must have the Environment Admin role or a custom role with equivalent permissions to enable or disable the PingOne Remote MCP Server.

For this EA release, enabling the PingOne Remote MCP Server provides access to all of the available PingOne MCP tools. During EA, you should enable the server in non-production environments only. More granular tool controls will be introduced in a future release.

New system application

We’ve also added a new PingOne MCP Server system application. This application allows administrators to access and use the PingOne Remote MCP server to manage the environment’s configuration and data. It’s enabled by default and can’t be disabled.

A screenshot of the PingOne Applications page showing the new MCP Server system application.

Learn more

Learn more about the PingOne Remote MCP Server in the Build with AI documentation.