Environment: Production Purpose: Configure PingFederate as an OpenID Connect (OIDC) Identity Provider for NPI's Auth0 tenant, for Single Sign-On into Vantage.
Auth0 Callback URI: https://auth.npi-digital.com/login/callback Auth0 Sign-out Redirect URI: https://auth.npi-digital.com/logout
This guide uses OIDC. If your organization prefers SAML 2.0, use the companion guide, Configuring PingFederate (SAML) SSO for Vantage.
1. Prerequisites
Before starting, verify:
- You have Administrator access to the PingFederate administrative console.
- The OAuth authorization server is enabled in PingFederate, with an Access Token Manager and an OpenID Connect Policy configured.
- An IdP adapter or authentication policy is mapped to persistent grants, so PingFederate can authenticate users for OAuth requests.
- Your PingFederate discovery endpoint is reachable from the internet:
https://<your-pingfederate-host>/.well-known/openid-configuration. Auth0 reads it to find your authorization, token, and signing-key endpoints.
2. Create the OAuth Client
- Sign in to the PingFederate administrative console.
- Navigate to Applications → OAuth → Clients and click Add Client.
2.1 General Settings
- Client ID: a unique identifier, for example
npi-vantage-auth0-prod. It cannot be changed after you save. - Name: for example
NPI Vantage (Auth0) - Prod. - (Optional) Description: "Enterprise Single Sign-On client used by Auth0 for the NPI Vantage production environment."
2.2 Client Authentication
- Select Client Secret.
- Check Change Secret, then click Generate Secret.
- Copy the secret now. PingFederate will not display it again after you save.
2.3 Redirection URIs
In Redirection URIs, add each of the following and click Add:
https://auth.npi-digital.com/login/callback
https://npi-prod.us.auth0.com/login/callbackThis is where PingFederate sends the user after successful authentication.
⚠️ These must match exactly. Do not use wildcards.
2.4 Grant Types and Response Types
- Allowed Grant Types: select Authorization Code only.
- Restrict Response Types (recommended): check it and select
codeonly. - Bypass Authorization Approval: check it, so users are not shown a consent screen on each sign-in.
2.5 OpenID Connect Settings
- ID Token Signing Algorithm: RSA using SHA-256 (RS256).
- ID Token Key Management Encryption Algorithm: No Encryption (the default). Tell NPI before go-live if your policy requires encrypted ID tokens.
- Policy: select the OIDC policy you will configure in Section 3, or leave Default if that policy is your default.
Click Save.
3. Configure Scopes and ID Token Claims
NPI's Auth0 connection requests the scopes openid, profile, and email, and Vantage needs the user's email to match their account. Your OIDC policy must release these claims in the ID token.
3.1 Scopes
Go to System → OAuth Settings → Scope Management and confirm profile and email exist as common scopes (openid is built in). Add any that are missing.
3.2 OpenID Connect Policy
- Go to Applications → OAuth → OpenID Connect Policy Management. Edit your default policy, or click Add Policy to create one for Vantage.
- Manage Policy: select an Access Token Manager that issues signed JWTs. Check Include User Info in ID Token.
- Attribute Contract: confirm or add the claims in the table below.
- Attribute Scopes: map
emailto theemailscope, andgiven_name,family_name, andnameto theprofilescope. - Contract Fulfillment: map each claim to its source, as in the table. Click Next, then Save.
- If you created a new policy, select it in the OAuth client's Policy field (Section 2.5).
Claim | Required | Typical source (LDAP / Active Directory) |
|---|---|---|
| Yes |
|
| Yes |
|
| Recommended | Text value |
| Recommended |
|
| Recommended |
|
| Optional |
|
Use the claim names exactly as shown, all lowercase. The email must match the email the user is invited to Vantage with.
If you also need group membership in Vantage, add a groups claim and tell NPI the claim name.
4. Collect Values and Share Details with the Vantage Team
4.1 Issuer and Discovery URL
Your issuer is the PingFederate Base URL shown in System → Server Settings → Federation Info, for example https://sso.yourcompany.com. Confirm the discovery document loads in a browser:
https://sso.yourcompany.com/.well-known/openid-configurationThe issuer value in that document is the value to send NPI.
4.2 Client Credentials
From the OAuth client you created in Section 2, copy:
- ✅ Client ID
- ✅ Client Secret (copied when you generated it)
Share the client secret securely, through a password manager share or an encrypted channel agreed with your implementation engineer. Do not send it over email.
4.3 Final Deliverables
Value | Example |
|---|---|
Issuer / Discovery URL |
|
Client ID |
|
Client Secret |
|
Email domains to route to PingFederate |
|
Test user email |
|
Redirect URIs (configured, for reference) |
|
Logout URI (for reference) |
|
5. Test the Connection
Once NPI confirms the Auth0 connection is live, test with the user you named in Section 4.3.
- Open a private or incognito browser window.
- Go to
https://www.npi-digital.comand enter the test user's work email. - Confirm you are redirected to your PingFederate sign-in page, not the Vantage password prompt.
- Sign in. You should land in Vantage, signed in as the test user, with no consent screen.
If a step fails, note the time and the error text, and send them to NPI along with your PingFederate server log entry for that sign-in.
6. Common Errors to Avoid
Issue | Resolution |
|---|---|
| Both redirect URIs in Section 2.3 must be registered exactly, with no trailing slash |
| Confirm Authorization Code is an allowed grant type on the client |
| Client secret was mistyped or regenerated; send NPI the current secret |
Missing email in Vantage | Check the |
User sees a consent screen | Check Bypass Authorization Approval on the client |
User is sent to the Vantage password prompt | Email domain is not registered with NPI; send the missing domain |
Auth0 cannot reach PingFederate | The discovery endpoint must be reachable from the internet over HTTPS with a publicly trusted certificate |
7. Quick Checklist
- Created OAuth client in PingFederate
- Client secret generated and stored securely
- Both redirect URIs configured
- Authorization Code grant enabled; consent bypassed
- OIDC policy releases
email,given_name,family_name - Discovery URL confirmed reachable
- Issuer, client ID, client secret, domains, and test user sent to NPI
- Test sign-in completed
Need Help?
If you encounter issues or need assistance, contact your Vantage implementation engineer or reach us at support@npi-digital.com.
Sources
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article