Ping Identity SAML2 SSO with Flexopus
With the Ping Identity SAML2 SSO integration, your employees can log in to Flexopus directly using their existing company login credentials – securely, easily and without additional passwords.
What is the Ping Identity SAML2 integration?
The Ping Identity SAML2 integration connects Flexopus to your existing Ping Identity environment via the SAML2 (Security Assertion Markup Language) protocol. SAML2 is a widely used open standard for the secure exchange of authentication data between an Identity Provider (IdP) – in this case Ping Identity – and an application such as Flexopus.
During registration, Ping Identity verifies the user's identity and securely transmits the relevant user information – such as email address, name and department – to Flexopus. Additionally, optional user management can be set up via the SCIM 2.0 protocol to automatically synchronize users and groups between Ping Identity and Flexopus.
What is the purpose of integration?
The integration allows companies to centrally control access to Flexopus via Ping Identity. Administrators can define directly in Ping Identity which users or groups should have access to Flexopus – without manual maintenance in Flexopus.
Typical use cases for integration:
- Employees log in to Flexopus using their existing company login details – no separate account is necessary.
- New user profiles in Flexopus are automatically created upon the first successful SSO login, without manual creation by administrators.
- User attributes such as name, email address, department and job title are taken directly from Ping Identity and kept up to date in Flexopus.
- Optional: SCIM 2.0 allows users and groups to be automatically provisioned and deprovisioned, ensuring that access always reflects the current status in Ping Identity.
How easy is the integration?
Setting up the Ping Identity SAML2 integration takes place in just a few steps and requires no in-depth technical knowledge. In the Ping Identity Admin console, Flexopus is created as a SAML2 application and linked to the Flexopus metadata URL. The user attributes are then mapped and the connection is activated in the Flexopus settings.
Ready to start? For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- Central access management: User rights are managed exclusively in Ping Identity – no duplicate maintenance in Flexopus is necessary.
- Automatic user creation: New employees automatically receive a Flexopus profile upon their first SSO login – without any manual effort for administrators.
- Multi-factor authentication (MFA) support: The security policies from Ping Identity, including MFA, automatically apply to Flexopus login.
- Fewer passwords, more security: Employees use their familiar company login credentials – no separate Flexopus password is required.
- Data minimization: Only the necessary user attributes are transferred – no excessive data exchange.
- Optional SCIM provisioning: In addition to SSO login, users and groups can be automatically synchronized to further reduce administrative overhead.
- Included free of charge: SAML2 SSO integration is included in Flexopus at no extra cost.
Further integrations
Questions and answers
Are existing user accounts deleted in Flexopus when a user is deactivated in Ping Identity?
If SCIM is not configured, the Flexopus account will remain, but the user will no longer be able to log in via SSO because Ping Identity will deny access. With active SCIM provisioning, deactivated or deleted users are automatically deactivated in Flexopus as well.
Can I change a user's UPN (Unique Principal Name) afterwards?
The UPN is a unique identifier and should not be changed after setup. A change can result in a duplicate user profile being created in Flexopus. Should a change still be necessary, please contact Flexopus support at support@flexopus.com. The team can selectively reset the UPN entries to enable a clean transfer.
Are user profile pictures synchronized via SAML2?
No, the SAML2 protocol does not support the transfer of profile pictures. Profile pictures must be manually uploaded by users to Flexopus.
Does Flexopus support IdP-initiated login (IdP-Initiated SSO)?
Flexopus offers a solution for IdP-initiated logins: The IdP-initiated login is converted into a secure SP-initiated login via the initiate-sp-login parameter in the RelayState. This protects against potential security risks such as man-in-the-middle attacks, which can occur with classic IdP-initiated logins.
What happens if I receive an error message when logging in?
A common reason for login errors is incorrectly configured URLs or attributes. Check the settings using the instructions in the Help Center. Should the problem persist, please contact support@flexopus.com – the Flexopus team can use the server logs to identify the exact cause.

