PingOne (SAML)
The PingOne cloud platform from PingIdentity provides SSO identity management. Cloudflare Access supports PingOne as a SAML identity provider.
-
In your PingIdentity environment, go to Connections > Applications.
-
Select Add Application.
-
Enter an Application Name.
-
Select SAML Application.
-
Select Configure.
-
To fill in your Cloudflare Access metadata:
- Select Import from URL.
- Set the Import URL to:
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/saml-metadatawhere
<your-team-name>is your Cloudflare One team name. 3. Select Import. 4. Save the configuration. -
In the Configuration tab, select Download metadata and save the XML metadata file. This file will be used in a later step to add PingOne to Cloudflare One.
-
In the Attribute Mappings tab, add the following required attributes (case sensitive) and select Save.
Application attribute Outgoing value emailEmail Address givenNameGiven Name surNameFamily Name These SAML attributes tell Cloudflare Access who the user is.
-
Set the application to Active.
-
In Cloudflare One ↗, go to Integrations > Identity providers.
-
Under Your identity providers, select Add new identity provider.
-
Select SAML.
-
Upload your PingOne XML metadata file.
-
(Optional) To enable SCIM, refer to Synchronize users and groups.
-
(Optional) Under Optional configurations, configure additional SAML options.
-
Select Save.
You can now test your connection and create Access policies based on the configured login method and SAML attributes.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark