> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fiddler.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# PingOne SAML

> Learn how to configure Fiddler with PingOne for Single Sign-On (SSO) using the Security Assertion Markup Language (SAML) protocol.

## Overview

This integration allows your users to sign in to Fiddler using their existing PingOne account, without needing a separate Fiddler password. Users are automatically provisioned on their first successful login — no manual invitations required.

## Prerequisites

Before starting, ensure you have:

* **PingOne Administrator Access**: Permissions to create and configure applications in your PingOne environment.
* **Fiddler AuthN Administrator Access**: Org Owner role in Fiddler's AuthN management console.
* **Deployment Information**: The hostname of your Fiddler deployment, e.g. `idpexample.dev.fiddler.ai`.

## Configuring PingOne and Fiddler for Integration

<Steps>
  <Step title="Fiddler AuthN Console Sign-in">
    <Info>
      The URL to the Fiddler AuthN management console is your Fiddler instance base URL prepended with `authn-`. For example, if your Fiddler base URL is `https://idpexample.dev.fiddler.ai` then you will access the AuthN management console at `https://authn-idpexample.dev.fiddler.ai`.
    </Info>

    Sign in using the AuthN console Org Owner user account credentials provided by your Fiddler representative.

    <img src="https://mintcdn.com/fiddlerai/LFezQzAOZ4GbBOtH/images/authn-console-login-page.png?fit=max&auto=format&n=LFezQzAOZ4GbBOtH&q=85&s=a85c93e86c371a7c5fee59bbb16bb73d" alt="Fiddler AuthN console sign-in page" width="3024" height="1656" data-path="images/authn-console-login-page.png" />
  </Step>

  <Step title="Select Your Organization">
    Ensure your organization is selected in the dropdown. You may see the *fiddler* organization, but this is reserved for system use and should not be edited. Here we are using the *idpexample* organization.

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-organization-settings.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=c738d283925bf5ae30acfc0e033161b2" alt="Fiddler AuthN console home page" width="3024" height="1652" data-path="images/authn-console-organization-settings.png" />
  </Step>

  <Step title="Navigate to Identity Providers in Settings">
    Select *Settings* tab from the top menu and then select *Identity Providers* from the left navigation menu.

    <img src="https://mintcdn.com/fiddlerai/LFezQzAOZ4GbBOtH/images/authn-console-organization-identity-providers.png?fit=max&auto=format&n=LFezQzAOZ4GbBOtH&q=85&s=7442828d5a4956079023c4a781a10daf" alt="Fiddler AuthN console add provider page" width="3024" height="1652" data-path="images/authn-console-organization-identity-providers.png" />
  </Step>

  <Step title="Add and Configure New SAML Provider">
    1. Select the *SAML* option in the *Add provider* section, which brings up the Sign in with SAML form.
    2. Enter a name for the integration. This name is displayed on the SSO login button on the Fiddler sign-in page, so choose one your users will recognize.
    3. Paste the following placeholder value into the *Metadata XML* text area. AuthN needs it to generate the URLs used when you create the PingOne app integration; you will replace it in a later step.

    **File:** `Placeholder Metadata XML value`

    ```
    PD94bWwgdmVyc2lvbj0iMS4wIj8+DQo8bWQ6RW50aXR5RGVzY3JpcHRvciB4bWxuczptZD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOm1ldGFkYXRhIg0KICAgICAgICAgICAgICAgICAgICAgdmFsaWRVbnRpbD0iMjAyNS0wOC0zMFQxMzo0NToxM1oiDQogICAgICAgICAgICAgICAgICAgICBjYWNoZUR1cmF0aW9uPSJQVDYwNDgwMFMiDQogICAgICAgICAgICAgICAgICAgICBlbnRpdHlJRD0iaHR0cDovL2xvY2FsaG9zdDo4MDgwIj4NCiAgICA8bWQ6U1BTU09EZXNjcmlwdG9yIEF1dGhuUmVxdWVzdHNTaWduZWQ9ImZhbHNlIiBXYW50QXNzZXJ0aW9uc1NpZ25lZD0iZmFsc2UiIHByb3RvY29sU3VwcG9ydEVudW1lcmF0aW9uPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6cHJvdG9jb2wiPg0KICAgICAgICA8bWQ6TmFtZUlERm9ybWF0PnVybjpvYXNpczpuYW1lczp0YzpTQU1MOjEuMTpuYW1laWQtZm9ybWF0OnVuc3BlY2lmaWVkPC9tZDpOYW1lSURGb3JtYXQ+DQogICAgICAgIDxtZDpBc3NlcnRpb25Db25zdW1lclNlcnZpY2UgQmluZGluZz0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmJpbmRpbmdzOkhUVFAtUE9TVCINCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBMb2NhdGlvbj0iaHR0cDovL2xvY2FsaG9zdDo4MDgwL2NvbnN1bWUvZGF0YSINCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBpbmRleD0iMSIgLz4NCiAgICAgICAgDQogICAgPC9tZDpTUFNTT0Rlc2NyaXB0b3I+DQo8L21kOkVudGl0eURlc2NyaXB0b3I+
    ```

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-provider-form.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=27682f9b7fa4f71232f80e50c53a2f5a" alt="Fiddler AuthN console new SAML configuration" width="3024" height="1650" data-path="images/authn-console-ping-saml-provider-form.png" />
  </Step>

  <Step title="Save the SAML Provider">
    Select the *Create* button and then select the *Save* button. You will be returned to the Organization Settings page.

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-identity-providers.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=0a76c2f8238a88bf573442cfb8c545c6" alt="Fiddler AuthN console saving new SAML IdP" width="3024" height="1648" data-path="images/authn-console-ping-saml-identity-providers.png" />
  </Step>

  <Step title="Copy the SAML URLs">
    Select your IdP from the list. Four URLs are displayed — copy the following three for the PingOne app integration steps:

    * ZITADEL Metadata URL
    * ZITADEL ACS Login Form URL
    * ZITADEL ACS Intent API URL

          <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-redirect-urls.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=c8508a912a92ee1615322e6ff8fe8731" alt="Fiddler AuthN console SAML IdP URLs required for PingOne configuration" width="3024" height="1650" data-path="images/authn-console-ping-saml-redirect-urls.png" />
  </Step>

  <Step title="Create the PingOne App">
    1. In the PingOne admin console, navigate to *Applications* and select the *+* icon.
    2. Enter a name for your application, e.g. `Fiddler IdP Example`, select *SAML Application*, then select *Configure*.

           <img src="https://mintcdn.com/fiddlerai/i69CIvSBIFc1KMda/images/ping-saml-application-configure.png?fit=max&auto=format&n=i69CIvSBIFc1KMda&q=85&s=0d4dcb68a044da11743e12a452a6b199" alt="PingOne admin console SAML application name and type" width="3022" height="1658" data-path="images/ping-saml-application-configure.png" />
  </Step>

  <Step title="Configure the PingOne App">
    1. Under *Provide Application Metadata*, select *Manually Enter*.
    2. Enter the *ZITADEL ACS Login Form URL* into the *ACS URL* text box.
    3. Add the *ZITADEL ACS Intent API URL* as a second ACS URL.
    4. Enter the *ZITADEL Metadata URL* into the *Entity ID* text box.
    5. Select *Save*.

           <img src="https://mintcdn.com/fiddlerai/i69CIvSBIFc1KMda/images/ping-saml-metadata.png?fit=max&auto=format&n=i69CIvSBIFc1KMda&q=85&s=26746921ae7d590b6dce16b0f9ae3d54" alt="PingOne admin console SAML configuration" width="3024" height="1656" data-path="images/ping-saml-metadata.png" />
  </Step>

  <Step title="Configure the Application Settings">
    1. Open the created application and go to the *Configuration* section. Select the edit icon and ensure *Sign Assertion and Response* is selected, then select *Save*.

           <img src="https://mintcdn.com/fiddlerai/i69CIvSBIFc1KMda/images/ping-saml-sign-assertion-response.png?fit=max&auto=format&n=i69CIvSBIFc1KMda&q=85&s=91b5671fa9329fafe7038c7f93fa722a" alt="PingOne admin console sign assertion and response setting" width="3024" height="1654" data-path="images/ping-saml-sign-assertion-response.png" />
    2. Go to the *Attribute Mappings* section. Select the edit icon and add the following mappings, then select *Save*:

       1. Name=`email`, Value=`Email Address`
       2. Name=`firstName`, Value=`Given Name`
       3. Name=`lastName`, Value=`Family Name`
       4. Name=`groups`, Value=`Group Names`

           <img src="https://mintcdn.com/fiddlerai/i69CIvSBIFc1KMda/images/ping-saml-attribute-mappings.png?fit=max&auto=format&n=i69CIvSBIFc1KMda&q=85&s=d9dd0277611524ba491601ca406dd785" alt="PingOne admin console SAML attribute mappings" width="3024" height="1654" data-path="images/ping-saml-attribute-mappings.png" />
    3. At the top of the application, toggle it to *Active*.
    4. Go to the *Overview* section, then under *Connection Details*, copy the *IDP Metadata URL*.

           <img src="https://mintcdn.com/fiddlerai/i69CIvSBIFc1KMda/images/ping-saml-overview.png?fit=max&auto=format&n=i69CIvSBIFc1KMda&q=85&s=326c3a1153bfde3f877e51e04f5fd76e" alt="PingOne admin console application overview with IDP Metadata URL" width="3020" height="1654" data-path="images/ping-saml-overview.png" />
  </Step>

  <Step title="Replace the Placeholder Metadata XML">
    1. Return to the identity provider form in the Fiddler AuthN console (where you left off in step 4 — *Add and Configure New SAML Provider*).
    2. Clear the *Metadata XML* text area.
    3. Paste the *IDP Metadata URL* copied from PingOne into the *Metadata URL* text box.

           <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-metadata-url.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=7bd81a28f231ebee27374f430081eba3" alt="Fiddler AuthN console Metadata URL" width="3024" height="1654" data-path="images/authn-console-ping-saml-metadata-url.png" />
  </Step>

  <Step title="Configure Additional Parameters">
    1. Expand the *optional* section.
    2. Ensure the *Automatic create* and *Automatic update* checkboxes are selected.
    3. Set the *Determines whether an identity will be prompted to be linked to an existing account* dropdown to *Check for existing Username*.

           <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-saml-create-update-username.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=17aa81a1a075868f881c353388de056c" alt="Fiddler AuthN console automatic create/update and check existing username settings" width="3024" height="1656" data-path="images/authn-console-saml-create-update-username.png" />
  </Step>

  <Step title="Save the Configuration Changes">
    Select the *Save* button. You will be returned to the Organization Settings page.

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-identity-providers.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=0a76c2f8238a88bf573442cfb8c545c6" alt="Fiddler AuthN console with newly created PingOne SAML IdP" width="3024" height="1648" data-path="images/authn-console-ping-saml-identity-providers.png" />
  </Step>

  <Step title="Activate the PingOne SAML IdP">
    1. Select your IdP from the list and select the *Activate* button on the identity provider page.

           <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-redirect-urls.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=c8508a912a92ee1615322e6ff8fe8731" alt="Fiddler AuthN console activate new PingOne SAML IdP" width="3024" height="1650" data-path="images/authn-console-ping-saml-redirect-urls.png" />
    2. Close the settings and then select *Login Behavior and Security* from the left nav menu and ensure the *External login allowed* checkbox is selected.

           <img src="https://mintcdn.com/fiddlerai/LFezQzAOZ4GbBOtH/images/authn-console-login-behaviour-security.png?fit=max&auto=format&n=LFezQzAOZ4GbBOtH&q=85&s=3bb781d4b4c483dc8676f0f6d55a6f62" alt="Fiddler AuthN console allow external login behavior" width="3024" height="1652" data-path="images/authn-console-login-behaviour-security.png" />
    3. Select the *Save* button.

           <img src="https://mintcdn.com/fiddlerai/LFezQzAOZ4GbBOtH/images/authn-console-login-behaviour-security-external.png?fit=max&auto=format&n=LFezQzAOZ4GbBOtH&q=85&s=a9207dddebc85b5297d3352e953db453" alt="Fiddler AuthN console external login allowed" width="3024" height="1654" data-path="images/authn-console-login-behaviour-security-external.png" />
  </Step>

  <Step title="Create a Custom Action">
    Select the *Actions* tab from the top menu.

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-action-script.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=b7573a870f7c48d409e4a2e12f9690b2" alt="Fiddler AuthN console new custom Action script" width="3024" height="1648" data-path="images/authn-console-ping-saml-action-script.png" />

    1. Select the *New* button in the *Scripts* section to create a new action script.
    2. Copy the *PingOne SAML Action Script* below and paste it into the script text area.
    3. Enter `setAttributesOnPingSAMLAuth` in the *Name* text box.
    4. Select the *Add* button.

    **File:** `PingOne SAML Action Script`

    ```javascript theme={null}
    function setAttributesOnPingSAMLAuth(ctx, api) {
        let firstName = ctx.v1.providerInfo.attributes["firstName"];
        let lastName = ctx.v1.providerInfo.attributes["lastName"];
        let email = ctx.v1.providerInfo.attributes["email"];
        let groups = ctx.v1.providerInfo.attributes["groups"];

        let nameParts = [firstName, lastName];
        let filteredParts = nameParts.filter(part => part);
        let displayName = filteredParts.join(' ');

        if (firstName != undefined) {
          api.setFirstName(firstName);
        }
        if (lastName != undefined) {
          api.setLastName(lastName);
        }
        if (email != undefined) {
          email = String(email).toLowerCase();
          api.setEmail(email);
          api.setEmailVerified(true);
          api.setPreferredUsername(email);
        }
        if (displayName) {
          api.setDisplayName(displayName);
        }

        api.v1.user.appendMetadata('fiddler_authentication_type', 'SSO:PING:SAML');
        if (groups === null || groups === undefined) {
          groups = []
        }
        api.v1.user.appendMetadata('fiddler_groups', groups);
    }
    ```
  </Step>

  <Step title="Configure the Action Trigger">
    Scroll down to the *Flows* section.

    <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-ping-saml-action-trigger.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=bed3b29ed433450a069ee1f988e02b54" alt="Fiddler AuthN console new Action trigger creation" width="3024" height="1646" data-path="images/authn-console-ping-saml-action-trigger.png" />

    1. Select the *External Authentication* option for the *Flow Type* dropdown.
    2. Select the *+ Add trigger* button.
    3. Select the *Post Authentication* option for the *Trigger Type* dropdown.
    4. Select the *setAttributesOnPingSAMLAuth* option for the *Actions* dropdown.
    5. Select the *Save* button.
  </Step>

  <Step title="Set the Organization SSO Authentication Type">
    Add an organization metadata key so Fiddler can correctly identify and process this SSO connection. Set this once during setup.

    1. Go to the *Metadata* section and select *Edit*.

           <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-organization-metadata.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=8e07886ca3bf84dcc9074e9c354e768e" alt="Fiddler AuthN console organization metadata section" width="3024" height="1652" data-path="images/authn-console-organization-metadata.png" />
    2. Select the *Add* button, then enter the key `fiddler_sso_authentication_type` with the value `SSO:PING:SAML`.

           <img src="https://mintcdn.com/fiddlerai/0YAzrIgYU8gLFpZN/images/authn-console-organization-metadata-ping-saml.png?fit=max&auto=format&n=0YAzrIgYU8gLFpZN&q=85&s=8f4ae6d615e6ed1e32a7d63596cdd206" alt="Fiddler AuthN console organization metadata with PingOne SAML authentication type" width="3024" height="1650" data-path="images/authn-console-organization-metadata-ping-saml.png" />
    3. Select the *Save* button next to the new entry.
  </Step>

  <Step title="Validate the Integration">
    <Info>
      Before validating, ensure your PingOne user account is assigned to the new PingOne application you created.
    </Info>

    1. Open your Fiddler URL (e.g. `https://idpexample.dev.fiddler.ai`).
    2. Ensure you see the Fiddler sign-in page and that it displays an SSO login button labeled with the name you configured (e.g. *PingOne SAML*).

           <img src="https://mintcdn.com/fiddlerai/rI_REZccoRLqD6i6/images/fiddler-ping-saml-login.png?fit=max&auto=format&n=rI_REZccoRLqD6i6&q=85&s=c3e33fe2bcdaf3cefb2527b26e14565d" alt="Fiddler application homepage displaying the new SSO login method in addition to the email sign-in form" width="3024" height="1652" data-path="images/fiddler-ping-saml-login.png" />
    3. Select the button and confirm that the Fiddler application loads.

           <img src="https://mintcdn.com/fiddlerai/rI_REZccoRLqD6i6/images/fiddler-successful-login.png?fit=max&auto=format&n=rI_REZccoRLqD6i6&q=85&s=577af651008c8412526f47b9e1115df2" alt="Fiddler application landing page" width="3024" height="1658" data-path="images/fiddler-successful-login.png" />

    <Info>
      The first user to sign in to the Fiddler application is automatically assigned the Fiddler Org Admin role; subsequent members are Org Members by default.
    </Info>
  </Step>
</Steps>

## Getting Help

If sign-in fails, check the **PingOne Audit Log** (*Monitoring → Audit*) for the failed attempt and its reason. For Fiddler-side issues, see the [SSO Authentication Guide](/reference/access-control/sso-authentication-guide). If the issue persists, contact your Fiddler representative with the specific error message.

## Important Notes

* **Data Storage**: Fiddler stores the following profile attributes from PingOne: first name, last name, display name, email address, and group memberships (used to map users to Fiddler teams).
* **API Access**: For programmatic API access, users create an API key from the *Credentials* tab in Fiddler's *Settings* page.
* **Single Authentication Method**: Users can only authenticate via either SSO or email authentication, not both.

## Next Steps

After successful integration:

* **Train Users**: Provide guidance on accessing Fiddler through PingOne SSO.
* **Configure Teams**: Map your identity provider groups to Fiddler teams — see [Mapping AD Groups to Fiddler Teams](/reference/access-control/mapping-ad-groups-to-fiddler-teams).
* **Test Group Sync**: Verify automatic group synchronization is working as expected.
* **Monitor Usage**: Review authentication logs and user access patterns.
