> Full SurrealDB documentation index: https://surrealdb.com/docs/llms.txt

# PingFederate

Configure PingFederate as an identity provider for single sign-on in SurrealDB. Create a SAML 2.0 SP connection in PingFederate and add a PingFederate connection in SurrealDB Studio.

Connect PingFederate to SurrealDB to allow members of your organisation to sign in with their Ping Identity credentials. The connection uses SAML 2.0. You start an SP connection in PingFederate, add a connection in SurrealDB Studio, and then finish the SP connection with values from Studio.

Before you start, [verify the email domain](/docs/manage/enterprise/single-sign-on.md#step-1-verify-an-email-domain) your company uses. You also need administrator access to your PingFederate server.

The values PingFederate needs from SurrealDB include the connection's name, which exists only after you create the connection. That is why the setup finishes in PingFederate.

## Step 1: Start an SP connection

1. In PingFederate, create an SP connection that uses **Browser SSO** with the **SAML 2.0** protocol.
2. Send each person's email address as the NameID, or as an email attribute.
3. Export the signing certificate that PingFederate uses for this connection, in PEM format.

If PingFederate asks for the ACS URL or the entity ID before you can save, enter a temporary value such as `https://auth.surrealdb.com/login/callback` and replace it in step 3.

## Step 2: Add the connection in SurrealDB

1. Open **Single sign-on** in your enterprise and add a new connection.
2. Select **PingFederate**.
3. Under **Name the connection**, enter a **Display name**. Members see this name on the sign-in screen.
4. Under **Enter the PingFederate details**, enter:
    - **PingFederate server URL**: the base URL of your server, for example `https://ping.example.com`.
    - **X.509 signing certificate**: the PEM-encoded certificate, starting with `-----BEGIN CERTIFICATE-----`.
5. Under **Route sign-in domains**, select the verified domains to send to this connection. This is optional, and you can change it later.
6. Select **Create connection**.

Studio opens the **Sign-on** tab of the new connection.

## Step 3: Finish the SP connection

The **Set up PingFederate** section of the **Sign-on** tab shows the values for the SP connection, with a copy button beside each. `<connection>` is the connection's name.

| Value                                 | Form                                                                 |
| ------------------------------------- | -------------------------------------------------------------------- |
| Assertion Consumer Service (ACS) URL  | `https://auth.surrealdb.com/login/callback?connection=<connection>`   |
| Entity ID                             | `urn:auth0:auth0surrealdb:<connection>`                              |
| Metadata URL                          | `https://auth.surrealdb.com/samlp/metadata?connection=<connection>`   |

In the SP connection, set the partner's entity ID to the entity ID and the ACS endpoint to the ACS URL, or import both from the metadata URL. Then activate the SP connection.

## Next steps

If you did not route a domain when you created the connection, [route one now](/docs/manage/enterprise/single-sign-on.md#step-3-route-domains-to-the-connection). Then [choose the applications](/docs/manage/enterprise/single-sign-on.md#step-4-choose-the-applications) that people can sign in to with this connection.
