Enable Ping SSO for your Canary Console by configuring SAML settings, creating an SSO app, and sharing your metadata for secure, seamless single sign-on access.
Enable Single Sign-On from Ping Identity to your Canary Console with this guide.
Step 1: Find your SAML parameters
Log in to your Console, click the white Gear Icon on the top right-hand side of your screen, select Global Settings, then expand the SAML section at the bottom of the page.
You will find the info for your Console (pictured below) that you'll need for Step 3 of the process.
Step 2: Create a SAML Application in Ping Identity
Log in to your Ping Admin Console and expand the Applications menu, then select Applications and finally hit the Plus Icon to create a new App.
From here you'll want to enter an Application Name, Icon and select SAML Application for the type.
Once complete, hit Configure.
Step 3: Application Configuration.
On the popup, select Manually Enter for the metadata.
Enter the SAML parameters from your Canary Console received in Step 1.
- Enter your ACS URL :
https://XXX.canary.tools/saml/acs - Enter your SP Entity ID :
https://XXX.canary.tools/
Finally hit Save.
Your application has now been created, and we'll want to make some tweaks.
First, hit the Attributes button, to modify how users will log in.
Your Canary Console expects and email address in order to identify users, and you'll want to map the saml_subject attribute to Email Address.
Hit Save once complete.
Once complete, you can enable the application by toggling toggle on the top right.
Step 4: Share SAML Metadata
Before the SSO integration can be used, we'll need to load your metadata onto your canary Console.
Simply share your Metadata URL with the support team here, and we'll have your SSO setup in no time.
Assigning users or groups to the Canary Application
With your SSO setup, you'll want to grant access to your users to access your Canary Console.
With your Canary application open, select the Access button.
At the popup, assign your user groups to the app, and finally hit Save once complete.
Logging into your Console via SSO
You'll know it's working when you see your Console Login page show a Login with SSO button:
Click the button to initiate the SSO login.
You'll also be able to login to your Console by clicking on your Canary app panel inside the PingID dashboard: