Set Up a Ping Identity (SAML) Application¶
Ensure that you have Administrator access to your Ping Identity Account and Trust3 AI.
Follow these steps to create and configure a Ping Identity application for Single Sign-On (SSO):
Step 1: Log in to Your Ping Identity Admin Console¶
- Log in using your administrator credentials.
Step 2: Create a New SAML Application¶
- In the Admin Console, navigate to Applications from the left-side menu.
- Click on Applications under the Applications tab.
- On the Applications page, click + Add Application and select SAML Application.
Step 3: General Information¶
- In the General Information section, provide a descriptive name for your application in the Application Name field.
For example:Trust3 AI SAML-SSO - (Optional) Upload a logo for the application if needed.
- Click Configure to proceed to the Configuration page.
Step 4: SAML Configuration¶
-
Choose the Manually Enter option to provide the SAML metadata manually:
- Fill in the required fields with the metadata information.
Field Value Example ACS URLs https://na.trust3ai.com/SingleSignOnService/receiveResponseEntity ID trust3ai_portal- click Save to manually save the entered metadata.
Step 5: Configure SAML Connection¶
-
In the Attribute Mapping section, map user attributes:
Attribute Name Value Description UserIdusernameThe unique identifier for the user, typically their login name. EmailemailThe email address associated with the user. FirstNamegivenNameThe user's first name. LastNameFamily NameThe user's last name or surname. memberOfGroupNamesGroup NamesThis is optional attribute, the names of the groups to which the user belongs, for role mapping. -
Click Save to proceed.
Step 6: Assign Users/Groups to the Application¶
- Go to the Access tab of the newly created application.
- Click Add and select Users or Groups.
- Choose the users or groups you want to assign and click Add.
Important
It is assumed that the user is already mapped with the appropriate groups before being assigned to the application in Ping Identity.
Step 7: Review Your Configuration¶
- Review all the entered information and confirm that it is accurate.
- Click on the Toggle Button to enable the application.
Step 8: Obtain Identity Provider Metadata¶
- Go to the Configuration tab of the newly created application.
- Scroll down to the SAML Settings section.
- Click on Download Metadata to download the metadata XML file.
This file will be used for configuring the SSO in the Trust3 AI portal.
Step 9: Copy Initiate Single Sign-On URL¶
- Go to the Overview tab of the newly created application.
- Scroll down to the Initiate Single Sign-On URL section.
- Click the Copy Button to copy the URL for the
Identity Provider Urlin the Trust3 AI portal.
You have successfully set up a Ping Identity application for SAML-SSO in the Ping Identity console. This application is now ready to be integrated with the Trust3 AI portal.
Configure Ping Identity in your Trust3 AI account.¶
In Trust3 AI, follow these steps to access the Single Sign-On settings:
- Go to the Settings menu.
- Navigate to Identity.
- Enable Single Sign-On.
Reference image from Trust3 AI for better guidance: 
| Display Name | Description | Example Value | Optional/Required |
|---|---|---|---|
Entity Id | Entity ID for SAML configuration | trust3ai_portal | Required |
Identity Provider Url | Identity Provider URL | https://auth.pingone.asia/73c19f54-fd7b/saml20/idp/startsso?spEntityId=trust3ai_portal | Required |
Identity Provider Metadata | Metadata (XML file) | sso_saml.xml | Required |
UserName Attribute | UserName attribute for SAML user | UserId | Required |
Email Attribute | Email attribute for SAML user | Email | Required |
FirstName Attribute | FirstName attribute for SAML user | FirstName | Optional |
LastName Attribute | LastName attribute for SAML user | LastName | Optional |
Username Conversion in SSO¶
This setting determines how usernames are generated during SSO login when the Username Attribute value contains an email address.
Username Format Options¶
-
When the toggle is ON: The system uses the email prefix (the part before @) as the username. Example:
jane.doe@xyz.com→jane.doe -
When the toggle is OFF: The system uses the full email address as the username. Example:
jane.doe@xyz.com→jane.doe@xyz.com
Important Considerations¶
Possible Conflict: Email Already in Use
A conflict may occur if the email address is already associated with another user in the system. This may prevent successful login or account linking during SSO authentication.
Example Scenario: When a user attempts to log in with email jane.doe@xyz.com, but this email is already associated with username jane.doe, the login will fail due to the conflict.
Resolution Steps: An administrator must delete the existing user from Settings → Users, then ask the user to sign in via SSO again.
Configuration Impact
- New SSO logins will use the configured username format
- Existing users will be affected by this change on their next login attempt.
Troubleshooting
If you experience issues with SSO login, refer to the SSO Login Troubleshooting Guide for detailed steps and solutions.
Important
- Entity ID: Used to configure the Identity Provider (IdP).
- Identity Provider URL: URL obtained in Step 9, where users will be redirected for SSO login.
- Identity Provider Metadata: Use the Metadata XML file downloaded in Step 8 for seamless SSO configuration.
- User Attributes: Ensure that the correct user attributes (
UserId,Email,FirstName,LastName) are mapped from Ping Identity to Trust3 AI.
These variables ensure seamless integration between Ping Identity and Trust3 AI for SAML-SSO.
Role Mapping For Ping Identity¶
Role mapping allows you to translate roles or groups from your Ping Identity Identity Provider (IdP) into specific roles within Trust3 AI. This ensures that users have the correct permissions and access when they log into Trust3 AI.
What is Role Name Attributes?¶
This attribute in your Identity Provider (IdP) contains the user’s roles or group information. It is used to identify the roles or groups the user belongs to in the IdP.
What is Role Mapping?¶
This configuration maps roles or groups from the Identity Provider (IdP) to corresponding roles in Trust3 AI. If a specific role from the IdP matches a role defined in the role mapping configuration, that role is assigned to the user in Trust3 AI. If no mapping is defined, the default role, ROLE_USER, is automatically assigned to the user.
| Variable Name | Description | Example |
|---|---|---|
Role Name Attribute | Role name attributes for user. | memberOfGroupNames |
Role Mapping | Role mapping for user. | Identity Provider (IdP) Role: example_role → Example Role: ACCOUNT_ROLE |
Reference image of Role Mapping from Trust3 AI: 
Example:¶
- Identity Provider (IdP) Role or Group:
saml_admin - Mapped Trust3 AI Role:
ACCOUNT_ADMIN
In this example, if a user has the role saml_admin in Ping Identity, they will automatically be assigned the ACCOUNT_ADMIN role in Trust3 AI.
Important
New Users:
Role mapping only applies to newly created users after the mapping has been configured.
By properly configuring role mapping, you ensure that users are granted appropriate access levels within Trust3 AI based on their roles or group memberships from the Identity Provider (IdP). This simplifies user management and ensures seamless integration with your organization’s existing identity infrastructure.
Once the configuration is complete, you can test the setup by attempting to log in to the Trust3 AI portal using your Ping Identity credentials. This will help verify that the Single Sign-On (SSO) integration is working correctly.