Configuring PingFederate (OIDC) SSO for Vantage

Modified on Thu, 8 Oct at 10:27 AM


Environment: Production Purpose: Configure PingFederate as an OpenID Connect (OIDC) Identity Provider for NPI's Auth0 tenant, for Single Sign-On into Vantage.


Auth0 Callback URI: https://auth.npi-digital.com/login/callback Auth0 Sign-out Redirect URI: https://auth.npi-digital.com/logout


This guide uses OIDC. If your organization prefers SAML 2.0, use the companion guide, Configuring PingFederate (SAML) SSO for Vantage.


1. Prerequisites

Before starting, verify:

  • You have Administrator access to the PingFederate administrative console.
  • The OAuth authorization server is enabled in PingFederate, with an Access Token Manager and an OpenID Connect Policy configured.
  • An IdP adapter or authentication policy is mapped to persistent grants, so PingFederate can authenticate users for OAuth requests.
  • Your PingFederate discovery endpoint is reachable from the internet: https://<your-pingfederate-host>/.well-known/openid-configuration. Auth0 reads it to find your authorization, token, and signing-key endpoints.

2. Create the OAuth Client

  1. Sign in to the PingFederate administrative console.
  2. Navigate to Applications → OAuth → Clients and click Add Client.

2.1 General Settings

  • Client ID: a unique identifier, for example npi-vantage-auth0-prod. It cannot be changed after you save.
  • Name: for example NPI Vantage (Auth0) - Prod.
  • (Optional) Description: "Enterprise Single Sign-On client used by Auth0 for the NPI Vantage production environment."

2.2 Client Authentication

  1. Select Client Secret.
  2. Check Change Secret, then click Generate Secret.
  3. Copy the secret now. PingFederate will not display it again after you save.

2.3 Redirection URIs

In Redirection URIs, add each of the following and click Add:

https://auth.npi-digital.com/login/callback
https://npi-prod.us.auth0.com/login/callback

This is where PingFederate sends the user after successful authentication.

⚠️ These must match exactly. Do not use wildcards.

2.4 Grant Types and Response Types

  • Allowed Grant Types: select Authorization Code only.
  • Restrict Response Types (recommended): check it and select code only.
  • Bypass Authorization Approval: check it, so users are not shown a consent screen on each sign-in.

2.5 OpenID Connect Settings

  • ID Token Signing Algorithm: RSA using SHA-256 (RS256).
  • ID Token Key Management Encryption Algorithm: No Encryption (the default). Tell NPI before go-live if your policy requires encrypted ID tokens.
  • Policy: select the OIDC policy you will configure in Section 3, or leave Default if that policy is your default.

Click Save.

3. Configure Scopes and ID Token Claims

NPI's Auth0 connection requests the scopes openid, profile, and email, and Vantage needs the user's email to match their account. Your OIDC policy must release these claims in the ID token.

3.1 Scopes

Go to System → OAuth Settings → Scope Management and confirm profile and email exist as common scopes (openid is built in). Add any that are missing.

3.2 OpenID Connect Policy

  1. Go to Applications → OAuth → OpenID Connect Policy Management. Edit your default policy, or click Add Policy to create one for Vantage.
  2. Manage Policy: select an Access Token Manager that issues signed JWTs. Check Include User Info in ID Token.
  3. Attribute Contract: confirm or add the claims in the table below.
  4. Attribute Scopes: map email to the email scope, and given_name, family_name, and name to the profile scope.
  5. Contract Fulfillment: map each claim to its source, as in the table. Click Next, then Save.
  6. If you created a new policy, select it in the OAuth client's Policy field (Section 2.5).


Claim

Required

Typical source (LDAP / Active Directory)

sub

Yes

objectGUID or another stable, unique ID

email

Yes

mail

email_verified

Recommended

Text value true

given_name

Recommended

givenName

family_name

Recommended

sn

name

Optional

displayName


Use the claim names exactly as shown, all lowercase. The email must match the email the user is invited to Vantage with.

If you also need group membership in Vantage, add a groups claim and tell NPI the claim name.

4. Collect Values and Share Details with the Vantage Team

4.1 Issuer and Discovery URL

Your issuer is the PingFederate Base URL shown in System → Server Settings → Federation Info, for example https://sso.yourcompany.com. Confirm the discovery document loads in a browser:

https://sso.yourcompany.com/.well-known/openid-configuration

The issuer value in that document is the value to send NPI.

4.2 Client Credentials

From the OAuth client you created in Section 2, copy:

  • ✅ Client ID
  • ✅ Client Secret (copied when you generated it)


Share the client secret securely, through a password manager share or an encrypted channel agreed with your implementation engineer. Do not send it over email.


4.3 Final Deliverables

Value

Example

Issuer / Discovery URL

https://sso.yourcompany.com/.well-known/openid-configuration

Client ID

npi-vantage-auth0-prod

Client Secret

************ (shared securely)

Email domains to route to PingFederate

yourcompany.com, subsidiary.com

Test user email

jane.doe@yourcompany.com

Redirect URIs (configured, for reference)

https://auth.npi-digital.com/login/callback, https://npi-prod.us.auth0.com/login/callback

Logout URI (for reference)

https://auth.npi-digital.com/logout


5. Test the Connection

Once NPI confirms the Auth0 connection is live, test with the user you named in Section 4.3.

  1. Open a private or incognito browser window.
  2. Go to https://www.npi-digital.com and enter the test user's work email.
  3. Confirm you are redirected to your PingFederate sign-in page, not the Vantage password prompt.
  4. Sign in. You should land in Vantage, signed in as the test user, with no consent screen.

If a step fails, note the time and the error text, and send them to NPI along with your PingFederate server log entry for that sign-in.


6. Common Errors to Avoid

Issue

Resolution

invalid_redirect_uri or redirect error page

Both redirect URIs in Section 2.3 must be registered exactly, with no trailing slash

unauthorized_client

Confirm Authorization Code is an allowed grant type on the client

invalid_client at sign-in

Client secret was mistyped or regenerated; send NPI the current secret

Missing email in Vantage

Check the email scope and the email claim mapping in the OIDC policy

User sees a consent screen

Check Bypass Authorization Approval on the client

User is sent to the Vantage password prompt

Email domain is not registered with NPI; send the missing domain

Auth0 cannot reach PingFederate

The discovery endpoint must be reachable from the internet over HTTPS with a publicly trusted certificate


7. Quick Checklist

  • Created OAuth client in PingFederate
  • Client secret generated and stored securely
  • Both redirect URIs configured
  • Authorization Code grant enabled; consent bypassed
  • OIDC policy releases email, given_name, family_name
  • Discovery URL confirmed reachable
  • Issuer, client ID, client secret, domains, and test user sent to NPI
  • Test sign-in completed

Need Help?

If you encounter issues or need assistance, contact your Vantage implementation engineer or reach us at support@npi-digital.com.


Sources

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article