# Ping Identity

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity
Last updated: 2026-09-25

Learn how to configure Ping Identity as an identity provider for NocoDB.

This article briefs about the steps to configure Ping Identity as Identity service provider for NocoDB

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`
2. Select `Authentication (SSO)`
3. Click on `New Provider` button
4. On the Popup modal, Specify a `Display name` for the provider; note that, this name will be used to display the provider on the login page
5. Retrieve `Redirect URL`; this information will be required to be configured later with the Identity Provider

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Ping Identity, Configure NocoDB as an Application

1. Access your [PingOne account](https://www.pingidentity.com/en/account/sign-on.html) and navigate to the homepage.
2. Click on `Add Environment` from the top right corner.
3. On the `Create Environment` screen,
   * Opt for `Build your own solution`
   * In the `Select solution(s) for your Environment` section, select `PingOne SSO` from `Cloud Services`
   * Click `Next`
   * Provide a name and description for the environment,
   * Click `Next`
4. Access the newly created environment and go to `Connections` > `Applications` from the sidebar.
5. Within the Applications homepage, initiate the creation of a new application by clicking the "+" icon.
6. On the "Add Application" panel:
   * Input the application name and description.
   * Choose "OIDC Web App" as the Application Type and click "Configure"
7. From your application,
   * Go to `Configurations` tab
   * Click on `Edit` button
   * Check `Refresh Token` option
   * Copy `Authorization URL`, `Token URL`, `Userinfo URL` & `JWK Set URL` from the `Endpoints` section
   * From `Generals` dropdown, copy `Client ID` & `Client Secret`
   * `Save`
8. From `Resources` tab,
   * Click `Edit`
   * Select `openid` `profile` `email` from `Scopes`
9. Switch toggle button in the top right corner to `On` to activate the application.

### NocoDB, Configure Ping Identity as an Identity Provider

1. In NocoDB, open `Account Settings` > `Authentication` > `OIDC`. On the "Register OIDC Identity Provider" modal, insert the following information:
   * Insert `Client ID` retrieved in step (9) above as `Client ID`
   * Insert `Client Secret` retrieved in step (9) above as `Client Secret`
   * Insert `Authorization URL` retrieved in step (9) above as `Authorization URL`
   * Insert `Token URL` retrieved in step (9) above as `Token URL`
   * Insert `Userinfo URL` retrieved in step (9) above as `Userinfo URL`
   * Insert `JWK Set URL` retrieved in step (9) above as `JWK Set URL`
   * Set `Scope` as `openid` `profile` `email` `offline_access`
   * In the Username Attribute field, indicate the name of the claim that represents the user's email. The default value is set to "email."

For Sign-in's, user should be able to now see `Sign in with <SSO>` option.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

For information about Ping Identity API Scopes, refer [here](https://docs.pingidentity.com/r/en-us/pingone/pingone_t_edit_scopes_for_an_application)

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and licensed self-hosted deployments (Business plan and above). For access, please reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on **Business plan**, the SSO configuration menu is available under **Settings** > **Single Sign-On (SSO)** in the workspace sidebar. Refer [here](/docs/product/account-settings/authentication#business-plan) for more details.
* **Domain Verification Required for Cloud Plans**: Before configuring OIDC SSO, you must verify your domain in NocoDB (required for both Business and Enterprise plans in the cloud). Only users with email addresses from verified domains can sign in via SSO. See [Domain Verification](/docs/product/account-settings/authentication#domain-verification) for details.

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta.md): Learn how to configure Okta as an identity provider for NocoDB.
- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0.md): Learn how to configure Auth0 as an identity provider for NocoDB.
- [Azure AD (Entra)](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad.md): Learn how to configure Azure AD as an identity provider for NocoDB.
