Ping Identity
Last updated
Was this helpful?
Last updated
Was this helpful?
Follow the below steps to configure your SSO login with Ping Identity.
In the Ping Identity Admin Console, go to Applications list (Connections
-> Applications
)
Click on +
icon and select OIDC Web App
in the Application Type
.
Configure the Application as follow:
Resource Access: Click on Resource Access (Overview
-> Resource Access
) and select email
and profile
scopes and click on Save.
Configuration: Click on Configuration tab, and click on Edit icon:
Under Response Type: Check Code
and Token
Under Grant Type: Check Authorization Code
and Implicit
Under Redirect URIs: Enter - https://app.balkan.id/authn/self-service/methods/oidc/callback/pingidentity-XXXXXXX
, where XXXXXX
should be the name of your PingIdentity account.
Under Token Endpoint Authentication Method: chooseClient Secret Post
.
Click Save.
Retrieve the Client ID
,Client Secret
and Issuer URL
and send them to BalkanID using a secure channel. We can extract the above data as follow:
Issuer URL: Under Configuration
Tab, under URLS
section, copy Issuer
Client ID: Under Configuration
Tab, under General
section, copy Client ID
Client Secret: Under Configuration
Tab, under General
section, copy Client Secret
Open PingIdentity Admin Console. You should be able to view BalkanID app under Applications.
Go to the login URI: https://app.balkan.id/?oidc=pingidentity-XXXXXX
where XXXXXX
should be the name of your Ping Identity account. Your account will be setup!
The steps to setup Ping Identity SSO for every user who previously already have a BalkanID application account (used to login via email & password or any prior SSO you already had in place) are as follows:
Go the company specific Ping Identity SSO link
Sign in with email & password or any prior SSO you already had in place. Then head to "Profile" -> Setup Ping Identity SSO.
Logout and log in with Ping Identity SSO.
The above is just a one-time activity that needs to be carried out by every existing user. Going forward, they can just login using Ping Identity SSO.