Ping Identity is a first-class enterprise connection over SAML 2.0. Users whose email domain matches the connection sign in through their Ping environment. MFA, session length, and lifecycle stay on Ping.

## Open the connection

In the [Authdog console](https://console.authdog.com/dashboard/authentication?tab=providers&category=enterprise):

1. Select the project and environment.
2. Open **Authentication > Providers** with the Enterprise filter.
3. Choose **Ping Identity**.
4. Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
5. In Ping, create a SAML application and paste those values exactly. The ACS URL is the Reply URL.

## Send Ping's values back

Provide Authdog with:

| Field | Value |
| --- | --- |
| **Connection name** | A name that shows in the Configured list |
| **IdP SSO URL** | The SSO URL from the Ping application |
| **IdP X.509 Certificate** | The signing certificate, including the BEGIN and END lines |

You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select **Fetch** or **Parse & autofill**. It does not refresh itself later. Re-import when Ping rotates the certificate.

Prefer RSA-SHA256 and SHA-256 if you turn on request signing.

## Route by email domain

In **Email domains (for SSO discovery)**, enter one or more domains separated by commas:

```text
acme.com, eu.acme.com
```

An entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.

## Test it

1. Use the connection's **Test** action.
2. Complete an SP-initiated sign-in.
3. Confirm Ping sends a stable subject and an email claim.
4. Repeat in production with production URLs. A [custom domain](/docs/custom-domains) change can change the callback. Update Ping with the URL currently shown in the form.

## Related

| Read | To learn how to |
| --- | --- |
| [Enterprise SSO](/docs/sso) | SAML fields, domain routing, and certificate rotation |
| [SAML 2.0](/marketplace/saml/setup) | The same form for an IdP that is not a named vendor |
| [Marketplace](/marketplace/ping) | The listing for this integration |
