PingFederate®
The PingFederate® offering from PingIdentity provides SSO identity management. Cloudflare Access supports PingFederate as a SAML identity provider.
 Set up PingFederate as an identity provider
- Log in to your Ping dashboard and go to Applications. 
- Select Add Application. 
- Select New SAML Application. 
- Complete the fields for name, description, and category. - These can be any value. A prompt displays to select a signing certificate to use. 
- In the SAML attribute configuration dialog select Email attribute > urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress. 
- In the Signature Policy tab, disable the option to Always Sign Assertion. 
- Leave the option enabled for Sign Response As Required. - This ensures that SAML destination headers are sent during the integration. - In versions 9.0 above, you can leave both of these options enabled. 
- A prompt displays to download the SAML metadata from Ping. - This file shares several fields with Cloudflare Access so you do not have to input this data. 
- In Zero Trust, go to Settings > Authentication. 
- Under Login methods, select Add new. 
- Select SAML. 
- In the IdP Entity ID field, enter the following URL: https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback- You can find your team name in Zero Trust under Settings > Custom Pages. 
- Fill the other fields with values from your Ping dashboard. 
- Select Save. 
To test that your connection is working, go to Authentication > Login methods and select Test next to the login method you want to test.
 Example API configuration