Skip to content

Ping SSO

Create a PingOne or PingFederate SAML 2.0 app with signed assertions and paste the metadata URL into Avaloi.

Create a SAML connection in PingOne or PingFederate, then paste its metadata URL into Avaloi. Only the Owner can save the connection.

Connect Ping

  1. Add a SAML application. In Ping, create a SAML 2.0 app. Set the ACS to https://api.avaloi.com/auth/saml/{company}/acs and the start URL to https://api.avaloi.com/auth/saml/{company}/start. Replace {company} with your company slug.
  2. Sign assertions. Avaloi requires signed assertions. Use your Ping signing certificate.
  3. Copy the metadata. Copy the IdP metadata URL or the issuer.
  4. Save in Avaloi. Open Company settings, then SSO. Choose SAML, paste the URL, add your domains, and save.
  5. Test, then enforce. Sign in through Ping. When that works, turn on Enforce SSO.

Quick answers

Avaloi refused the assertion. Check that assertions are signed with your Ping certificate and that the NameID is the user email.

PingOne or PingFederate? Either. The Avaloi side is the same: ACS, start URL, signed assertions, and the metadata URL.

Members are stuck in a redirect loop. Turn Enforce SSO off, fix the connection, test one login, then enforce again. See SSO.

API

  • GET /v1/companies/me/sso
  • PUT /v1/companies/me/sso

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.