Attribute sources are specific datastore or directory locations containing information that may be needed for the IdP adapter contract or the Token Authorization framework. You can use more than one attribute source when mapping values to the IdP adapter contract.

The PingFederate IdP server supports separate datastores to look up attributes for a single mapping. For example, you can query multiple datastores for values and map those values in one mapping, or query a datastore for a value and use that value as input for subsequent queries of other datastores.

Queries are executed in the order as shown on the Attribute Sources & User Lookup screen. Use the up and down arrows as needed to adjust the order.

If a required attribute (such as the user identifier username or subject for the HTML Form Adapter or the OpenToken IdP Adapter, respectively) cannot be fulfilled, the request fails.

  • If your use case requires only dynamic texts or results from OGNL expressions without any attributes from local datastores, skip to the next screen.
  • To add an attribute source, click Add Attribute Source.

    Repeat this step as needed to add another attribute source.

  • To modify an existing instance, select it by its name under Description.
  • To remove an existing instance or to cancel the removal request, click Delete or Undelete under Action.