Ping SSO
Create a PingOne or PingFederate SAML 2.0 app with signed assertions and paste its metadata URL into Avaloi.
Connect PingOne or PingFederate to Avaloi with SAML 2.0. Only the Owner can save the connection, and it is for Enterprise accounts. The full flow, including domain proof, testing, and mandatory sign-on, is in Single sign-on with SAML.
Connect PingOne or PingFederate
- Add a SAML application. In Ping, create a SAML 2.0 app.
- Add the Avaloi details. Set the ACS URL and the Entity ID from the Single sign-on page in Avaloi. Use the email address as the SAML_SUBJECT.
- Sign the assertion. Turn on assertion signing with your Ping signing certificate and SHA-256.
- Copy the IdP metadata URL.
- In Avaloi, open Company settings, then Single sign-on, then Enable. Paste the metadata URL, list your email domains, and save.
- Add the DNS TXT record Avaloi shows under Domain proof, choose Verify domain, then choose Test connection.
- Sign in once through Sign in with your company. When that works, turn on Mandatory single sign-on if you want it.
Quick answers
PingOne or PingFederate? Either. The Avaloi side is the same: the ACS URL, the Entity ID, signed assertions, and the metadata URL.
Avaloi refused the response.
Check that the assertion is signed, that the email is the NameID or the email attribute, and that the email is on a domain you verified. See the fixes in Single sign-on with SAML.
Members are stuck in a loop. The Owner can always sign in with a password. Turn Mandatory single sign-on off, fix the connection, run Test connection, then turn it on again.
API
GET /v1/companies/me/sso/sp-metadataPUT /v1/companies/me/ssoPOST /v1/companies/me/sso/test
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.