Set up SSO for Showpad with PingOne Updated January 08, 2025 09:15 Showpad offers a SAML-based Single Sign-On (SSO) service that allows users to access Showpad using their organization's credentials. This simplifies users' lives by requiring fewer usernames and passwords, as there is only one account to remember. This article describes how you can set up SSO for Showpad using PingOne as the Identity Provider (IDP). PingOne users are mapped to Showpad users by email address. Key features Users can access Showpad with their PingOne account Auto-provision & assign users to the right groups in Showpad Reduce security threats to sensitive data loss Centralized user, password, and authorization management You need this to succeed The beta Admin App enabled Feature availability depends on your subscription package Administrator account on both Showpad's Admin App and PingOne Basic PingOne knowledge Unique users in PingOne The quick way Create a new SAML 2.0 app in PingOne. Copy the PingOne IDP Metadata URL. Map PingOne and Showpad attributes. Add SSO Configuration in Showpad. Add PingOne Metadata. Verify attribute mappings. Do this step by step Note: We do our best to stay up to date with the platforms Showpad can connect with, however, we are not notified of any changes to their procedures. In PingOne, begin by adding a new SAML application. As an administrator, you may see a shortcut to add a new SAML application when you first log in. You can also click the Connections icon on the left menu and click the plus icon next to Applications. Provide a name, a description, and an optional icon for your application. Under Application Type, select SAML Application, and then click Configure. On the SAML Configuration page, select Manually Enter and add the following information: ACS URL - This is the URL of your Showpad domain with "/sso/acs" added to the end. This is a temporary placeholder that will be replaced with Showpad's dynamically generated URL once the configuration is created on the Showpad side. Entity ID - This is the URL of your Showpad domain. Click Save. This opens the application's details on the Overview tab. Select the Configuration tab and copy the IDP Metadata URL. Note: Alternatively, you can download the metadata in an XML file by clicking Download Metadata. Next, select the Attribute Mappings tab and click the pencil icon to define which PingOne attributes correspond to Showpad attributes. Define the PingOne attributes that correspond to Showpad. In addition to the saml_subject attribute, the email, firstname, and lastname Showpad attributes are mandatory. Click +Add to add additional attributes. In Showpad, users are identified by their username, which is always an email address. If this is not the case for your setup, be sure to select a different attribute (like Email Address) that is formatted as an email but still uniquely identifies the user to use for the saml_subject attribute. You can create new PingOne attributes and then build an Advanced Expression for the following Showpad attributes: Showpad Attribute Available Values Description Role Field tablet (users) or admin If an unrecognized value is presented to Showpad, the default value of tablet will be used. This constitutes a normal user. Group Assignment Field Showpad expects the value of this attribute to be a comma-separated list of group names. This is used to automatically provision users into Showpad groups.During sign-on, Showpad will assign the user to the given list of groups. If the group does not exist, Showpad will create it.Note that the name of the attribute will be specific to your setup. Click Save. In your Showpad organization, click the gear icon to open the settings and navigate to the Sign On in the left menu. Click Add Configuration, enter a name (e.g., PingOne SSO), and select the SAML 2.0 protocol in the dropdown menu. Click Next. If you downloaded the XML file from PingOne, select XML for the Metadata Source and paste the file's contents in the Metadata XML box. If not, select URL for the Metadata Source and enter the URL copied from PingOne in the Metadata URL field. Choose SHA-256 as the Hash Algorithm. If preferred, you can enable auto-provisioning by ticking the corresponding checkbox. Click Save. Click the info icon of your newly added configuration on the Sign-On overview page, and copy the Assertion Consumer Service Endpoint. In PingOne, open your Showpad application, click on the pencil icon, and paste the Assertion Consumer Service Endpoint into the ACS URLS field. Click Save. Enable the application by clicking the toggle next to your Showpad application name. Related articles 2025 Set up SSO for Showpad with AD FS How to log in on Showpad