Skip to content

Single sign-on

PingFederate

Connect PingFederate to SurrealDB to allow members of your organisation to sign in with their Ping Identity credentials. The connection uses SAML 2.0. You start an SP connection in PingFederate, add a connection in SurrealDB Studio, and then finish the SP connection with values from Studio.

Before you start, verify the email domain your company uses. You also need administrator access to your PingFederate server.

The values PingFederate needs from SurrealDB include the connection's name, which exists only after you create the connection. That is why the setup finishes in PingFederate.

  1. In PingFederate, create an SP connection that uses Browser SSO with the SAML 2.0 protocol.

  2. Send each person's email address as the NameID, or as an email attribute.

  3. Export the signing certificate that PingFederate uses for this connection, in PEM format.

If PingFederate asks for the ACS URL or the entity ID before you can save, enter a temporary value such as https://auth.surrealdb.com/login/callback and replace it in step 3.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select PingFederate.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the PingFederate details, enter:

    • PingFederate server URL: the base URL of your server, for example https://ping.example.com.

    • X.509 signing certificate: the PEM-encoded certificate, starting with -----BEGIN CERTIFICATE-----.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

Studio opens the Sign-on tab of the new connection.

The Set up PingFederate section of the Sign-on tab shows the values for the SP connection, with a copy button beside each. <connection> is the connection's name.

ValueForm
Assertion Consumer Service (ACS) URLhttps://auth.surrealdb.com/login/callback?connection=<connection>
Entity IDurn:auth0:auth0surrealdb:<connection>
Metadata URLhttps://auth.surrealdb.com/samlp/metadata?connection=<connection>

In the SP connection, set the partner's entity ID to the entity ID and the ACS endpoint to the ACS URL, or import both from the metadata URL. Then activate the SP connection.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?