PingOne for Workforce
Use PingOne for Workforce as Pomerium's OpenID Connect identity provider and apply Ping identity or group data to access policy.
Overview
PingOne for Workforce is the Ping Identity product covered by this guide. Pomerium can use it as an OpenID Connect identity provider for protected routes.
Using PingOne for Workforce as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.
PingOne for Workforce sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.
How it works
Create a PingOne OpenID Connect web application with the exact Pomerium callback and email attribute mapping. Enable the application. Configure Pomerium with the ping provider key, issuer, client ID, and client secret.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team registers Pomerium as an OpenID Connect client in PingOne for Workforce. Users sign in through PingOne for Workforce. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.
Considerations
- Use the PingOne for Workforce configuration for this integration.
- PingOne group claims contain IDs. Map and document the values that policy uses.
- Directory sync is separate and needs Pomerium Enterprise and a PingOne Worker application.
- PingOne for Workforce remains responsible for authentication, user lifecycle, and the identity data that it issues.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
