Ping Identity
This article gives the steps to configure Ping Identity as the identity provider for NocoDB.
NocoDB, Retrieve Redirect URL
- Go to
Account Settings. - Select
Authentication (SSO). - Click the
New Providerbutton. - In the dialog, type a
Display namefor the provider. The login page shows the provider with this name. - Copy the
Redirect URL. You need it later to configure the identity provider.

Ping Identity, Configure NocoDB as an Application
- Sign in to your PingOne account and go to the homepage.
- In the top-right corner, click
Add Environment. - On the
Create Environmentscreen:- Select
Build your own solution. - In the
Select solution(s) for your Environmentsection, selectPingOne SSOfromCloud Services. - Click
Next. - Type a name and a description for the environment.
- Click
Next.
- Select
- Open the new environment. In the sidebar, go to
Connections>Applications. - On the Applications homepage, click the "+" icon to create a new application.
- On the "Add Application" panel:
- Type the application name and description.
- For the Application Type, select "OIDC Web App". Then click "Configure".
- In your application:
- Go to the
Configurationstab. - Click the
Editbutton. - Select the
Refresh Tokenoption. - From the
Endpointssection, copyAuthorization URL,Token URL,Userinfo URL&JWK Set URL. - From the
Generalsdropdown, copyClient ID&Client Secret. - Click
Save.
- Go to the
- On the
Resourcestab:- Click
Edit. - From
Scopes, selectopenidprofileemail.
- Click
- In the top-right corner, set the toggle button to
On. This activates the application.
NocoDB, Configure Ping Identity as an Identity Provider
- In NocoDB, open
Account Settings>Authentication>OIDC. In the "Register OIDC Identity Provider" dialog, enter this information:- In
Client ID, enter theClient IDfrom step (9) above. - In
Client Secret, enter theClient Secretfrom step (9) above. - In
Authorization URL, enter theAuthorization URLfrom step (9) above. - In
Token URL, enter theToken URLfrom step (9) above. - In
Userinfo URL, enter theUserinfo URLfrom step (9) above. - In
JWK Set URL, enter theJWK Set URLfrom step (9) above. - Set
Scopetoopenidprofileemailoffline_access. - In the Username Attribute field, enter the name of the claim that contains the user's email. The default value is "email."
- In
Users now see the Sign in with <SSO> option on the sign-in page.

Post sign-out, refresh page (for the first time) if you do not see Sign in with SSO option
For information about Ping Identity API Scopes, refer here.
For more common questions and troubleshooting, see our SSO FAQ.
Availability
- OIDC SSO is available on NocoDB Cloud (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach out to sales team.
- On the Business plan, the SSO configuration menu is in the workspace sidebar, at Settings > Single Sign-On (SSO). For more details, refer here.
- Domain Verification Required for Cloud Plans: Verify your domain in NocoDB before you configure OIDC SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see Domain Verification.
Last updated on
Latest product updates?See Changelog