
Ping Federate
Use PingFederate identity context and enrich its tokens to drive fine-grained access decisions.
About PlainID + Ping Federate
The integration of PlainID with Ping offers organizations the ability to implement a continuous Authentication-Authorization process. Ping, being an Identity Provider (IdP), primarily focuses on managing the authentication process through well-defined protocols such as OIDC and SAML, resulting in an authentication token. However, the PlainID Ping Authorizer extends this process by dynamically computing and delivering a list of claims and groups, which are based on the policies defined within PlainID. These claims and groups are then used to enrich the token that Ping creates during the authentication process.
The goal of this token enrichment process is to dynamically and contextually generate and provide a list of claims and groups, as part of the login process. By doing so, organizations can ensure that the user is granted access to the resources they are entitled to. This integration provides a seamless experience for users and helps organizations enforce their access policies in a more efficient and effective way.
Technical Information
The PlainID Ping Authorizer allows enriching Ping's JWT as part of the login process. This is done by utilizing Pings’s webhook to obtain the relevant claims for the authenticating user from PlainID’s PDP. The Token Enrichment functionality is supported both by the PlainID Cloud-Based PDP, and the Hybrid, customer-hosted PlainID Policy Authorization Agent.
Architectures
- User logins to the application.
- The app initiates an authentication process (SSO) with Ping (IdP).
- As part of the authentication process, Ping sends a request to PlainID Authorizer via a webhook interface for authorization claims.
- The PDP dynamically calculates the access decision.
If needed, the Policy Information Point (PIP) pulls additional user or asset attributes from various data sources to calculate the access decision.PlainID Authorizer then returns the access decisions to be used for enriching the access token minted by Ping. - Ping provides the app with an access token containing the dynamically calculated access decision.

Technology
- Identity Providers
Capabilities
- Manage
- Enforce
Auth Patterns
- Token Enrichment
- Policy information point (PIP)
Need help integrating?
Our experts can help you architect the perfect authorization strategy for your stack.
Better Together
Connect Context. Centralize Policy. Enforce Everywhere.


