Configuring OpenID Connect (OIDC) Integration with PingOne - Rafay Product Documentation

OpenID Connect (OIDC) Integration

Follow the steps documented below to integrate your Org with an OIDC-compliant Identity Provider (IdP) such as Ping for Single Sign On (SSO).

Important

Only users with "Organization Admin" privileges can configure SSO in the Web Console.


Step 1: Create IdP in Web Console

The remaining fields: Client Secret, OP Domain URL, and Group Attribute Name must be populated after configuring the corresponding Ping application and retrieving these details from Ping.

Once these values are available, return to this page, complete the remaining fields, and then proceed with the setup.

Important

After completing the IdP configuration steps, the Redirect URL is generated in the Web Console. This Redirect URL must be added in the Ping Valid Redirect URIs field when creating the OIDC client.


Step 2: Configure Ping App

Step 3: Capture Client Credentials

🚨 Important: Ensure that the OP Domain URL includes the protocol prefix — http:// or https:// — to make it a valid URL. The process cannot proceed without a properly formatted URL.

Note: The OIDC discovery endpoint is also available in the connection details.

Once saved, the OIDC app is configured in PingOne.


Step 5: Webhook Configuration (Optional)

In the Web Console, configure the webhook if required, and click Save & Exit.

Once the configuration is complete, a verification email is sent to the admin email ID specified on the IdP Configuration page. Complete the verification before users can log in with OIDC

Note: On successful configuration, create a user and assign the user to the appropriate group in the IdP application.


Troubleshooting

Scenario 1: Missing Required Scopes or Group Attribute Mapping in PingOne

The IdP is configured in the Web Console, and the OIDC application is created in PingOne. However, required scopes such as email, profile, or the group attribute name configured in the Rafay console are not enabled or mapped in the PingOne application.

Resolution

If the group attribute name does not match between PingOne and the Web Console (as configured in Step 1), group-based access and role mapping will fail during authentication.