PingOne Advanced Identity Cloud

NameID mapper

Use a NameID mapper script to customize the value of the NameID attribute returned in the SAML assertion per SP.

Next-generation example script

SAML2 NameID Mapper Script

Script bindings

NameID mapper scripting API

Demonstrate a NameID mapper

Before you try the example, configure single sign-on using SAML 2.0 with Advanced Identity Cloud as the hosted IdP and set up a remote SP using the AM native console.

The following example modifies the NameID attribute in the assertion on the remote SP:

Create the script

  1. In the Advanced Identity Cloud admin console, create a script of type SAML2 NameID Mapper.

    This creates a blank next-generation script.

  2. Enter a suitable name for your script.

  3. In the JavaScript field, write a script to set a custom value for the NameID attribute. For example, the following script replaces instances of .com with .org in a user’s email address. Alternatively, uncomment the call to getIdentityNameID to set NameID to the user’s first and last name.

    /*
     * Retrieve nameID value from Java plugin and modify
    */
    function getModifiedNameID() {
      var nameIDValue = nameIDScriptHelper.getNameIDValue();
    
      if (nameIDValue.includes(".com")) {
          return nameIDValue.replace(".com", ".org");
      }
      return nameIDValue;
    }
    
    /*
     * Use identity binding to gather attributes
    */
    function getIdentityNameID() {
      var givenName = identity.getAttributeValues("givenName")[0];
      var lastName = identity.getAttributeValues("sn")[0];
    
      return givenName + "_" + lastName;
    }
    
    getModifiedNameID();
    //getIdentityNameID();

    Learn about the available bindings in the NameID mapper scripting API.

  4. Save your changes and close the editor.

Configure the remote SP

In the Advanced Identity Cloud admin console, the custom SAML 2.0 application you registered provides the hosted IdP configuration.

You must configure the NameID mapper script on the remote SP:

  1. Under Native Consoles > Access Management, go to Realms > Realm Name > Applications > Federation > Entity Providers and select the remote SP.

  2. Go to Assertion Processing > Account Mapper and select your script from the Name ID Mapper Script list.

  3. Save your changes.

Test the script

  1. Test your changes using an SP-initiated flow.

  2. Verify that the SAML 2.0 assertion shows an updated value, for example:

    <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
                 NameQualifier="idp"
                 SPNameQualifier="sp">bjensen@example.org</saml:NameID>