About PingID
PingID (PingOne) is Ping Identity’s cloud identity platform. The Serval PingID integration connects to your PingOne environment using a worker application with OAuth 2.0 client credentials. Workflows can manage the full identity lifecycle — look up, create, enable, disable, unlock, and delete users, reset passwords, revoke sessions, manage group membership — plus MFA devices, and call PingOne Management and MFA APIs with typed request schemas. The integration is marked Beta in Serval’s connect UI. Authentication: OAuth 2.0 client credentials against your PingOne environment. Serval exchanges the Client ID and Client Secret for short-lived bearer tokens athttps://auth.{region}/{environmentId}/as/token and attaches them to API requests at https://api.{region}.
Data sync: Background sync keeps Serval’s user directory, group catalog (with memberships), and application catalog current with the PingOne environment. Users support changed-since delta syncs via PingOne’s updatedAt filter; groups re-walk in full on a schedule because PingOne exposes no group change feed.
What the PingID integration enables
Get your credentials
You need your PingOne Environment ID, a worker application Client ID and Client Secret, and the region that hosts your environment.Open the PingOne admin console
Copy the Environment ID
Create or select a worker application
Copy the Client ID and Client Secret
Note your region
api.pingone.com), Canada (api.pingone.ca), Europe (api.pingone.eu), Asia-Pacific (api.pingone.asia), Australia (api.pingone.com.au), or Singapore (api.pingone.sg).Connect in Serval
Open the PingID connect form
Region (required)
Environment ID (required)
Client ID (required)
Client Secret (required)
Save and verify
Verifying the connection
Five health checks cover the integration:- Test PingID Connection — reads the environment record. Success:
Successfully authenticated with PingOne. Failure includes region- or credential-specific guidance from the integration. - List PingOne Users — fetches one user from
/environments/{environmentID}/users. Confirms Identity Data read access. - List PingOne Populations — reads populations in the environment. Confirms directory read access beyond authentication alone.
- List PingOne Groups — fetches one group. Confirms the read access the group workflows depend on.
- Manage PingOne Groups — creates and immediately deletes a
serval-healthcheck-prefixed group. Confirms the write access used by group management and access provisioning. This is a write check; if the delete fails, the check names the leftover group so you can remove it in the PingOne console.
Gotchas and troubleshooting
Use a Worker application, not a native OIDC app
Use a Worker application, not a native OIDC app
Region and Environment ID must match
Region and Environment ID must match
Disable, don't delete, for offboarding holds
Disable, don't delete, for offboarding holds
Password recovery codes require policy support
Password recovery codes require policy support
Newly created users have no password
Newly created users have no password
MFA reset workflows are destructive
MFA reset workflows are destructive
User targeting is by email
User targeting is by email
Groups are matched by exact name
Groups are matched by exact name
name eq filter. Group names are unique per environment only for environment-level groups — population groups can reuse a name across populations. When that happens the lookup refuses to guess; pass the optional population name input to scope it. Use List PingOne Groups to find the group spelling.Need help? Contact support@serval.com for assistance with your PingID integration.

