# PingOne Configuration

### PingOne

Login to the PingOne Admin portal <https://admin.pingone.com/>

<div align="left"><figure><img src="/files/phq6gj1xJkZKjEBO4eBN" alt=""><figcaption></figcaption></figure></div>

From the **PingOne** console menu, select **Applications >** **Application Catalog**

Search "**Keeper**" and click on the **"Keeper Password Manager - On-Prem SSO"** link to add the **Keeper Password Manager** application

<figure><img src="/files/aMuCem5IIoowlTRliFTu" alt=""><figcaption></figcaption></figure>

Click **Setup** to proceed to the next step

<figure><img src="/files/55sQPyNGOfVmaxLyWB3s" alt=""><figcaption></figcaption></figure>

Click **"Continue to Next Step"**

<figure><img src="/files/XDyec6y7z7qGtIBDwzRf" alt=""><figcaption></figcaption></figure>

On the Keeper SSO Connect Windows server, download the KeeperSsoMetadata.xml file and save it in a safe location.

Select **Export Metadata** on the Keeper SSO Connect.

![](https://docs.keeper.io/~gitbook/image?url=https%3A%2F%2F2635959690-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-legacy-files%2Fo%2Fassets%252F-LTyMp7XGU8wh-hRPBiB%252F-LlELLNsxWEt_eMnwY5u%252F-LlELNMKVPjjG2VsjMNB%252FConfig_1_D.png%3Falt%3Dmedia%26token%3D5b2815ac-7edf-4864-b030-6856a6ae3f4a\&width=768\&dpr=4\&quality=100\&sign=09b0b228072a26b7dee3f2ba537b0bbad664e7a9320fd5d9ef9d9daa4c5bf95e)

Back on the PingOne application configuration, select the **Select File** button and choose the file **KeeperSsoMetadata.xml**.

Then click on **Choose File** next to "Primary Verification Certificate" and upload a valid SSL certificate file.

Click **Continue to Next Step**

<figure><img src="/files/vTfBh6XAC9stDADsjNsq" alt=""><figcaption></figcaption></figure>

Enter the appropriate values associated with each attribute (see below image) and click **Continue to Next Step**

<figure><img src="/files/QJfJiiX72B7nfYoa2bli" alt=""><figcaption></figcaption></figure>

Modify the **Name** to appropriately match the Configuration Name of the SSO node from the **Keeper Admin Console**. Click **Continue to Next Step.**

<figure><img src="/files/v45zPcbNgQUUJjVsesD4" alt=""><figcaption></figcaption></figure>

You may choose to add PingOne user groups to your application. Click **Add** next to the group or groups you would like to add and click **Continue to Next Step**.

{% hint style="info" %}
PingOne users will have access to Keeper Password Manager by default. Assigning groups to Keeper Password Manager restricts access to only those groups.
{% endhint %}

<figure><img src="/files/w0k7Wy1hgQwEiMyxquac" alt=""><figcaption></figcaption></figure>

Click **Download** next to "SAML Metadata" and save the `.xml` file to a safe location.

<figure><img src="/files/aeEwpTH2ZygdXkWw6KYW" alt=""><figcaption></figcaption></figure>

Click **Finish** to complete the application setup wizard.

The **saml2-metadata-idp.xml** file will download to the browser. Copy this file to the Keeper SSO Connect server and upload it into the Keeper SSO Connect interface by dragging and dropping the file into the Setup screen: Select **Save**.

![](https://docs.keeper.io/~gitbook/image?url=https%3A%2F%2F2635959690-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-legacy-files%2Fo%2Fassets%252F-LTyMp7XGU8wh-hRPBiB%252F-LU2XMIWxEapTee8NpLo%252F-LU2bLIhZzK3yRbGibpe%252Fsso-step-115b.png%3Falt%3Dmedia%26token%3Db8ea323b-ff07-46f0-a851-dbf882298ed6\&width=768\&dpr=4\&quality=100\&sign=8541d4ef84058a1ac1aeca876ac4377950ce44af552fdb9d2855f3d9eb05d9b4)

The Keeper Application should be added and enabled.

<figure><img src="/files/Aob0X4twsHIrQr9spJfw" alt=""><figcaption></figcaption></figure>

**Important Note: In the Application Configuration section of your Ping Identity setup, ensure that the "Signing" section has "Sign Response" selected with "RSA\_SHA256" as the Signing Algorithm.**

Your Keeper SSO Connect setup is now complete!


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.keeper.io/sso-connect-on-prem/identity-provider-setup/pingone-configuration.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
