Ping Identity is an identity and access management (IAM) platform that securely manages and protects digital identities across enterprise environments. It enables organizations to protect customer data, maintain secure access to resources, and manage user accounts at scale.

The Ping Identity SSO integration in Profit.co allows organizations to configure single sign-on (SSO) using SAML, so users can authenticate via Ping Identity and access Profit.co without separate credentials. Additionally, SCIM-based user provisioning ensures that user lifecycle events in Ping Identity are automatically reflected in Profit.co.

What This Integration Supports

With the Ping Identity integration, you can:

  • Configure Ping Identity as a SAML identity provider for Profit.co
  • Enable SSO so users authenticate through Ping Identity
  • Map SAML attributes to Profit.co user fields
  • Provision, update, deactivate, and reactivate users via SCIM
  • Sync job titles and other profile attributes from Ping Identity to Profit.co

Prerequisites

Before starting, ensure the following requirements are met:

  • You have a valid Ping Identity account with administrator access
  • You are logged in as a Super User in Profit.co
  • You have the API Key and SCIM Key from Profit.co Settings → Security (required for user provisioning)
  • Configure Ping Identity SSO for Profit.co
  • Configure Ping Identity User Provisioning for Profit.co

Configure Ping Identity SSO for Profit.co

The following steps walk through setting up Ping Identity as the SAML identity provider for Profit.co.

Step 1

Log in to your Ping Identity account using your credentials.

  1. Open your browser and navigate to the Ping Identity admin console.
  2. Enter your Ping Identity administrator credentials.
  3. Click Log In to access the Ping Identity dashboard.
ping_signon

Create a New Environment

After logging in, you must set up a dedicated environment for Profit.co before creating the SAML application.

  1. From the Ping Identity home screen, open Environments from the left navigation panel.
  2. Click Create Environment.
  3. Choose Workforce solution and click Next.
  4. Select PingOne SSO and click Next.
create environment
  1. Fill in the environment details.
  2. Click Finish to create the environment.
  3. Open the newly created environment to proceed with the SAML application setup.
application

Step 2

  1. In your environment, click Connections in the left navigation panel.
  2. Go to Applications and click the + button to add a new application.
create environment
  1. Enter an Application Name (e.g., Profit.co) and an optional Description.
  2. Select the SAML application type.
  3. Click Configure to proceed.
config

Step 3

In the SAML configuration panel, click Manually Enter and provide the following values:

Field Value
ACS URL (US Region)
https://app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID
ACS URL (ME Region)
https://me1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID
ACS URL (SA Region)
https://sa1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID
ACS URL (EU2 Region)
https://eu2-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID
Entity ID User’s choice (must match what you configure in Profit.co)

Click Save to store the SAML configuration.

manually_enter

Step 4

  1. After saving the configuration, enable the toggle switch in the top-right corner of the application.
  2. Navigate to the Attribute Mappings tab within the application.
  3. Click Edit Attributes and configure the following mappings.
  4. Click Save after completing the attribute mapping.
attribute_manage

Step 5

  1. Navigate to the Access tab within the application.
  2. Add the user groups that should have access to Profit.co via SSO.
  3. Click Save to apply the group access configuration.
attribute_manage

Step 6

  1. Navigate to the Configuration tab of your SAML application.
  2. Copy the Issuer ID value — this will be used as the IDP Entity ID in Profit.co.
  3. Click Download Metadata to obtain the X509Certificate file.

Note: Downloading the X509Certificate is optional.

Now register Ping Identity in Profit.co:

  1. Log in to Profit.co and go to Settings → Integrations from the left navigation panel.
  2. Switch to the SAML SSO tab.
  3. Locate Ping Identity and click the Authorize button.
download
  1. Enter the Issuer ID and paste the X509Certificate content from the downloaded metadata file.

Note: The -X509Certificate field is optional when configuring authorization in Profit.co.

  1. Click Authorize to complete the registration.
download

Configure Ping Identity User Provisioning for Profit.co

SCIM-based provisioning keeps Profit.co user accounts in sync with Ping Identity. The following lifecycle events are supported:

  • Create Users — Users assigned to the Profit.co app in Ping Identity are automatically created in Profit.co User Management.
  • Update Users — Profile changes in Ping Identity are pushed to Profit.co.
  • Deactivate Users — Suspending a user or removing them from the Profit.co user group in Ping Identity deactivates the user in Profit.co.
  • Reactivate Users — Re-assigning a deactivated user to the Profit.co user group reactivates their Profit.co account.

Requirements

You need Admin access in Profit.co to retrieve the API Key and SCIM Key.

  • Navigate to Settings → Security in Profit.co
  • Copy your API Key and SCIM Key
  • The OAuth Access Token for SCIM is formed as: API_KEY:SCIM_KEY

Step 1

  1. Log in to your Ping Identity account and navigate to the Provisioning menu from the left navigation panel.
  2. Click the + symbol to create a new connection.
  3. On the Create a New Connection page, select the required Connection Type (Identity Store).
  4. Search for SCIM, select the SCIM Outbound connector, and click Next.
  5. Enter the Application Name and Description, then click Next.
provisioning sso_select

Step 2

Enter the following SCIM connection details:

Field Value
SCIM Base URL (US)
https://app.profit.co/app/rest/platform/auth/scim/v2
SCIM Base URL (EU)
https://eu2-app.profit.co/app/rest/platform/auth/scim/v2
SCIM Base URL (SA)
https://sa1-app.profit.co/app/rest/platform/auth/scim/v2
SCIM Base URL (ME)
https://me1-app.profit.co/app/rest/platform/auth/scim/v2
  1. Click Test Connection to validate the credentials.
test_connection
  1. Once the test is successful, click Next.
  2. On the next page, remove the User Filter Expression and set the User Identifier to Work Email.
  3. Update actions according to your preferences, click Finish, and enable the toggle on the confirmation page.

Note: If you don’t have a PingOne Directory set up, it will be created automatically during this step.

save

Step 3

  1. Return to the Provisioning menu and click + again.
  2. Click New Rule → Create Rule, then enter a Name and Description.
  3. On the Continue page, select your SCIM target application (created in Steps 1–2).
  4. Set the Source to your PingOne Directory.
  5. Click Save to create the rule.
create_rule

Step 4

  1. Click Edit User Filter within the provisioning rule.
  2. Set the filter condition as follows.
Attribute Group names
Operator Contains
Value The group name for which provisioning is required
  1. Click Save after setting the filter condition.
user_filter

Step 5

  1. Go to the Configurations page → Attribute Mapping section.
  2. Click Edit Attributes and configure the following mappings.
PingOne Directory Attribute Profit.co Attribute
Email Address userName
userName workEmail
Title title (click + Add to include this mapping)

3.Click Save after completing all attribute mappings.

add_save

Step 6

  1. Click the Enable toggle in the top-right corner of the provisioning connection.
  2. SCIM user provisioning will now begin. Users matching the filter condition will be synced to Profit.co.
disable

Step 7

Create a user in Ping Identity to verify the provisioning sync is working correctly.

  1. Navigate to Directory → Users and click the + button.
  2. Enter the Username / Email (use a new email address).
  3. Optionally enter a Title (Job Title) and Manager Email.
  4. Click Save — the user will be automatically synced to Profit.co based on the configured provisioning rule.
disable

Note: Any updates made in Ping Identity will automatically be reflected in Profit.co.

The default attributes supported for sync are,

  • Given Name
  • Family Name
  • Email Address
  • Active Status
  • Job Title

Create a Custom Attribute in Ping Identity

Custom attributes allow you to extend the default user schema in Ping Identity and sync additional fields, such as manager or role, to Profit.co.

  1. Navigate to Directory → User Attributes in the left navigation panel.
  2. Click the + button to add a new attribute.
  3. Select Declared and click Next.
custom attribute
  1. Fill in the attribute details:
Field Details
Name Required — unique identifier for the attribute (e.g., manager, role)
Display Name Optional — human-readable label shown in the UI
Description Optional — brief explanation of what the attribute captures
  1. Click Save to create the custom attribute.
custom attribute saved

Map Custom Attributes to Profit.co

Once the custom attributes are created, configure the attribute mapping in your provisioning connection to sync them to Profit.co.

  1. Navigate to Integrations → Provisioning in the left navigation panel.
  2. Open the Profit.co User Provisioning connection.
  3. Go to the Attribute Mapping tab.
  4. Click the Edit (pencil) icon to modify the attribute mappings.
  5. Add the following custom attribute mappings:
Ping Identity Attribute Profit.co Field
Manager (custom attribute) manager
Role (custom attribute) roles
Department (custom attribute) department
  1. Click Save to apply the updated attribute mappings.

Note: Custom attributes must be created in Ping Identity’s Directory → User Attributes before they can be mapped. Ensure the attribute names used in the mapping exactly match the names defined in the directory.

custom attribute mapping

Custom attributes for sync:

  • Manager
  • Role
  • Department

Summary

By configuring Ping Identity as the SAML identity provider and enabling SCIM-based user provisioning, Profit.co delivers a seamless single sign-on and user lifecycle management experience. Users authenticate securely through Ping Identity, while provisioning rules ensure user accounts in Profit.co stay automatically aligned with your organization’s identity directory — reducing administrative overhead and maintaining access governance at scale.