Ping Identity

This article gives the steps to configure Ping Identity as the identity provider for NocoDB.

NocoDB, Retrieve Redirect URL

  1. Go to Account Settings.
  2. Select Authentication (SSO).
  3. Click the New Provider button.
  4. In the dialog, type a Display name for the provider. The login page shows the provider with this name.
  5. Copy the Redirect URL. You need it later to configure the identity provider.

OIDC SSO Configuration OIDC SSO Configuration OIDC SSO Configuration

Ping Identity, Configure NocoDB as an Application

  1. Sign in to your PingOne account and go to the homepage.
  2. In the top-right corner, click Add Environment.
  3. On the Create Environment screen:
    • Select Build your own solution.
    • In the Select solution(s) for your Environment section, select PingOne SSO from Cloud Services.
    • Click Next.
    • Type a name and a description for the environment.
    • Click Next.
  4. Open the new environment. In the sidebar, go to Connections > Applications.
  5. On the Applications homepage, click the "+" icon to create a new application.
  6. On the "Add Application" panel:
    • Type the application name and description.
    • For the Application Type, select "OIDC Web App". Then click "Configure".
  7. In your application:
    • Go to the Configurations tab.
    • Click the Edit button.
    • Select the Refresh Token option.
    • From the Endpoints section, copy Authorization URL, Token URL, Userinfo URL & JWK Set URL.
    • From the Generals dropdown, copy Client ID & Client Secret.
    • Click Save.
  8. On the Resources tab:
    • Click Edit.
    • From Scopes, select openid profile email.
  9. In the top-right corner, set the toggle button to On. This activates the application.

NocoDB, Configure Ping Identity as an Identity Provider

  1. In NocoDB, open Account Settings > Authentication > OIDC. In the "Register OIDC Identity Provider" dialog, enter this information:
    • In Client ID, enter the Client ID from step (9) above.
    • In Client Secret, enter the Client Secret from step (9) above.
    • In Authorization URL, enter the Authorization URL from step (9) above.
    • In Token URL, enter the Token URL from step (9) above.
    • In Userinfo URL, enter the Userinfo URL from step (9) above.
    • In JWK Set URL, enter the JWK Set URL from step (9) above.
    • Set Scope to openid profile email offline_access.
    • In the Username Attribute field, enter the name of the claim that contains the user's email. The default value is "email."

Users now see the Sign in with <SSO> option on the sign-in page.

SAML SSO Configuration

Post sign-out, refresh page (for the first time) if you do not see Sign in with SSO option

For information about Ping Identity API Scopes, refer here.

For more common questions and troubleshooting, see our SSO FAQ.

Availability

  • OIDC SSO is available on NocoDB Cloud (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach out to sales team.
  • On the Business plan, the SSO configuration menu is in the workspace sidebar, at Settings > Single Sign-On (SSO). For more details, refer here.
  • Domain Verification Required for Cloud Plans: Verify your domain in NocoDB before you configure OIDC SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see Domain Verification.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX