Ping Identity is an identity and access management (IAM) platform that securely manages and protects digital identities across enterprise environments. It enables organizations to protect customer data, maintain secure access to resources, and manage user accounts at scale.
The Ping Identity SSO integration in Profit.co allows organizations to configure single sign-on (SSO) using SAML, so users can authenticate via Ping Identity and access Profit.co without separate credentials. Additionally, SCIM-based user provisioning ensures that user lifecycle events in Ping Identity are automatically reflected in Profit.co.
What This Integration Supports
With the Ping Identity integration, you can:
- Configure Ping Identity as a SAML identity provider for Profit.co
- Enable SSO so users authenticate through Ping Identity
- Map SAML attributes to Profit.co user fields
- Provision, update, deactivate, and reactivate users via SCIM
- Sync job titles and other profile attributes from Ping Identity to Profit.co
Prerequisites
Before starting, ensure the following requirements are met:
- You have a valid Ping Identity account with administrator access
- You are logged in as a Super User in Profit.co
- You have the API Key and SCIM Key from Profit.co Settings → Security (required for user provisioning)
- Configure Ping Identity SSO for Profit.co
- Configure Ping Identity User Provisioning for Profit.co
Configure Ping Identity SSO for Profit.co
The following steps walk through setting up Ping Identity as the SAML identity provider for Profit.co.
Step 1
Log in to your Ping Identity account using your credentials.
- Open your browser and navigate to the Ping Identity admin console.
- Enter your Ping Identity administrator credentials.
- Click Log In to access the Ping Identity dashboard.
Create a New Environment
After logging in, you must set up a dedicated environment for Profit.co before creating the SAML application.
- From the Ping Identity home screen, open Environments from the left navigation panel.
- Click Create Environment.
- Choose Workforce solution and click Next.
- Select PingOne SSO and click Next.
- Fill in the environment details.
- Click Finish to create the environment.
- Open the newly created environment to proceed with the SAML application setup.
Step 2
- In your environment, click Connections in the left navigation panel.
- Go to Applications and click the + button to add a new application.
- Enter an Application Name (e.g., Profit.co) and an optional Description.
- Select the SAML application type.
- Click Configure to proceed.
Step 3
In the SAML configuration panel, click Manually Enter and provide the following values:
| Field | Value |
|---|---|
| ACS URL (US Region) | https://app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID |
| ACS URL (ME Region) | https://me1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID |
| ACS URL (SA Region) | https://sa1-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID |
| ACS URL (EU2 Region) | https://eu2-app.profit.co/app/loginservlet?a=authorize&appCode=profit&integrationCode=PINGID |
| Entity ID | User’s choice (must match what you configure in Profit.co) |
Click Save to store the SAML configuration.
Step 4
- After saving the configuration, enable the toggle switch in the top-right corner of the application.
- Navigate to the Attribute Mappings tab within the application.
- Click Edit Attributes and configure the following mappings.
- Click Save after completing the attribute mapping.
Step 5
- Navigate to the Access tab within the application.
- Add the user groups that should have access to Profit.co via SSO.
- Click Save to apply the group access configuration.
Step 6
- Navigate to the Configuration tab of your SAML application.
- Copy the Issuer ID value — this will be used as the IDP Entity ID in Profit.co.
- Click Download Metadata to obtain the X509Certificate file.
Note: Downloading the X509Certificate is optional.
Now register Ping Identity in Profit.co:
- Log in to Profit.co and go to Settings → Integrations from the left navigation panel.
- Switch to the SAML SSO tab.
- Locate Ping Identity and click the Authorize button.
- Enter the Issuer ID and paste the X509Certificate content from the downloaded metadata file.
Note: The -X509Certificate field is optional when configuring authorization in Profit.co.
- Click Authorize to complete the registration.
Configure Ping Identity User Provisioning for Profit.co
SCIM-based provisioning keeps Profit.co user accounts in sync with Ping Identity. The following lifecycle events are supported:
- Create Users — Users assigned to the Profit.co app in Ping Identity are automatically created in Profit.co User Management.
- Update Users — Profile changes in Ping Identity are pushed to Profit.co.
- Deactivate Users — Suspending a user or removing them from the Profit.co user group in Ping Identity deactivates the user in Profit.co.
- Reactivate Users — Re-assigning a deactivated user to the Profit.co user group reactivates their Profit.co account.
Requirements
You need Admin access in Profit.co to retrieve the API Key and SCIM Key.
- Navigate to Settings → Security in Profit.co
- Copy your API Key and SCIM Key
- The OAuth Access Token for SCIM is formed as: API_KEY:SCIM_KEY
Step 1
- Log in to your Ping Identity account and navigate to the Provisioning menu from the left navigation panel.
- Click the + symbol to create a new connection.
- On the Create a New Connection page, select the required Connection Type (Identity Store).
- Search for SCIM, select the SCIM Outbound connector, and click Next.
- Enter the Application Name and Description, then click Next.
Step 2
Enter the following SCIM connection details:
| Field | Value |
|---|---|
| SCIM Base URL (US) | https://app.profit.co/app/rest/platform/auth/scim/v2 |
| SCIM Base URL (EU) | https://eu2-app.profit.co/app/rest/platform/auth/scim/v2 |
| SCIM Base URL (SA) | https://sa1-app.profit.co/app/rest/platform/auth/scim/v2 |
| SCIM Base URL (ME) | https://me1-app.profit.co/app/rest/platform/auth/scim/v2 |
- Click Test Connection to validate the credentials.
- Once the test is successful, click Next.
- On the next page, remove the User Filter Expression and set the User Identifier to Work Email.
- Update actions according to your preferences, click Finish, and enable the toggle on the confirmation page.
Note: If you don’t have a PingOne Directory set up, it will be created automatically during this step.
Step 3
- Return to the Provisioning menu and click + again.
- Click New Rule → Create Rule, then enter a Name and Description.
- On the Continue page, select your SCIM target application (created in Steps 1–2).
- Set the Source to your PingOne Directory.
- Click Save to create the rule.
Step 4
- Click Edit User Filter within the provisioning rule.
- Set the filter condition as follows.
| Attribute | Group names |
| Operator | Contains |
| Value | The group name for which provisioning is required |
- Click Save after setting the filter condition.
Step 5
- Go to the Configurations page → Attribute Mapping section.
- Click Edit Attributes and configure the following mappings.
| PingOne Directory Attribute | Profit.co Attribute |
| Email Address | userName |
| userName | workEmail |
| Title | title (click + Add to include this mapping) |
3.Click Save after completing all attribute mappings.
Step 6
- Click the Enable toggle in the top-right corner of the provisioning connection.
- SCIM user provisioning will now begin. Users matching the filter condition will be synced to Profit.co.
Step 7
Create a user in Ping Identity to verify the provisioning sync is working correctly.
- Navigate to Directory → Users and click the + button.
- Enter the Username / Email (use a new email address).
- Optionally enter a Title (Job Title) and Manager Email.
- Click Save — the user will be automatically synced to Profit.co based on the configured provisioning rule.
Note: Any updates made in Ping Identity will automatically be reflected in Profit.co.
The default attributes supported for sync are,
- Given Name
- Family Name
- Email Address
- Active Status
- Job Title
Create a Custom Attribute in Ping Identity
Custom attributes allow you to extend the default user schema in Ping Identity and sync additional fields, such as manager or role, to Profit.co.
- Navigate to Directory → User Attributes in the left navigation panel.
- Click the + button to add a new attribute.
- Select Declared and click Next.
- Fill in the attribute details:
| Field | Details |
| Name | Required — unique identifier for the attribute (e.g., manager, role) |
| Display Name | Optional — human-readable label shown in the UI |
| Description | Optional — brief explanation of what the attribute captures |
- Click Save to create the custom attribute.
Map Custom Attributes to Profit.co
Once the custom attributes are created, configure the attribute mapping in your provisioning connection to sync them to Profit.co.
- Navigate to Integrations → Provisioning in the left navigation panel.
- Open the Profit.co User Provisioning connection.
- Go to the Attribute Mapping tab.
- Click the Edit (pencil) icon to modify the attribute mappings.
- Add the following custom attribute mappings:
| Ping Identity Attribute | Profit.co Field |
| Manager (custom attribute) | manager |
| Role (custom attribute) | roles |
| Department (custom attribute) | department |
- Click Save to apply the updated attribute mappings.
Note: Custom attributes must be created in Ping Identity’s Directory → User Attributes before they can be mapped. Ensure the attribute names used in the mapping exactly match the names defined in the directory.
Custom attributes for sync:
- Manager
- Role
- Department
Summary
By configuring Ping Identity as the SAML identity provider and enabling SCIM-based user provisioning, Profit.co delivers a seamless single sign-on and user lifecycle management experience. Users authenticate securely through Ping Identity, while provisioning rules ensure user accounts in Profit.co stay automatically aligned with your organization’s identity directory — reducing administrative overhead and maintaining access governance at scale.