Ping SSO
Create a PingOne or PingFederate SAML 2.0 app with signed assertions and paste the metadata URL into Avaloi.
Create a SAML connection in PingOne or PingFederate, then paste its metadata URL into Avaloi. Only the Owner can save the connection.
Connect Ping
- Add a SAML application. In Ping, create a SAML 2.0 app. Set the ACS to
https://api.avaloi.com/auth/saml/{company}/acsand the start URL tohttps://api.avaloi.com/auth/saml/{company}/start. Replace{company}with your company slug. - Sign assertions. Avaloi requires signed assertions. Use your Ping signing certificate.
- Copy the metadata. Copy the IdP metadata URL or the issuer.
- Save in Avaloi. Open Company settings, then SSO. Choose SAML, paste the URL, add your domains, and save.
- Test, then enforce. Sign in through Ping. When that works, turn on Enforce SSO.
Quick answers
Avaloi refused the assertion. Check that assertions are signed with your Ping certificate and that the NameID is the user email.
PingOne or PingFederate? Either. The Avaloi side is the same: ACS, start URL, signed assertions, and the metadata URL.
Members are stuck in a redirect loop. Turn Enforce SSO off, fix the connection, test one login, then enforce again. See SSO.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.