Skip to main content

Ping One

Discover step-by-step instructions on configuring a Directory Sync with Ping One. Learn how to integrate your application with Okta.

How to start

SSO Ping One integration with Cryptr

Open console.pingone.eu (or other region)


SSO Ping One integration with Cryptr

Select your Environment (The Default Admin Env can't be used)

Declare an application

Environment Home screen

Click on "Integrations" on left sidebar


Environment Home screen

Then, click on "Provisioning"


Provisioning screen

Click on the "+" icon.

Provisioning screen

Then click on the "New Connection"

Provisioning screen - Type selection

Select "Identity Store"

Provisioning screen - Search

Search for "SCIM"

Provisioning screen - SCIM Result

Select the only result that should be "SCIM Outbound"

Provisioning screen

Click on "Next"


Configure your application with the supplied identification elements

Provisioning screen - General Config
  1. Enter the name of your app in the "Name" text zone
  2. Customize the icon and description of your app (optional)
  3. Click on "Next"

Provisioning screen - Auth config
  1. In the "SCIM BASE URL" field, paste the "SCIM Endpoint" value that you find on the right side of this tutorial 👉

  2. Select "OAuth2 Bearer Token" as the "Authentication Method."

Provisioning screen - Bearer config
  1. In the "OAuth Access Token" field, paste the "OAuth Access Token" value that you find on the right side of this tutorial 👉

  2. Select "Bearer" as the "Auth Type Header."

  3. Click on "Test Connection" and then "Next" if the test is successful.


Edit your Provisioning Settings

Provisioning screen - Preferences config
  1. In the "User Filter Expression" replace "username Eq" by "userName eq"

  2. Configure the others parameters depending on your needs.

  3. Click on "Finish"


Provisioning screen - App activation

Enable your provisioning App.


Setup your Connector (Rule)

Provisioning screen - Preferences config
  1. Now you can create a new Rule by clicking "+"

  2. Then click on "New Rule"


Provisioning screen - App activation
  1. Give a name (and description) to the new Rule.

  2. Then click on "Create Rule"


Provisioning screen - App activation
  • Add the newly created SCIM Connection to the Rule by clicking the "+" icon.

Provisioning screen - App activation
  • Save

Provisioning screen - App activation
  1. You can now edit the Configuration of the Rule

  2. Start by clicking on the "User Filter" then on the pen icon

  3. Add the rule you want, for example: "Enabled equals true". It will synchronize only active users. Save.


Provisioning screen - App activation
  • Now click on the "Attribute Mapping" then on the pen icon

Provisioning screen - App activation
  • Replace "Username" by "Email Address" for the "userName" mapping.

Provisioning screen - App activation
  1. Create a new Mapping by clicking "+ Add"

  2. Put "User ID" as PingOne Directory value

  3. Then put "externalId" as SCIM value and Save.


Provisioning screen - App activation
  • Enable your newly created Rule

Provisioning screen - App activation

Test your app's synchronization by assigning users to this application.