Build with AI

Authentication (early access)

The PingOne Remote Model Context Protocol (MCP) Server uses PingOne authentication to securely connect your artificial intelligence (AI) client to your PingOne environment. The first time you connect, your client opens a browser window and asks you to sign on with your PingOne credentials. After you sign on and approve access, your client can use PingOne MCP tools.

Before you begin

Make sure you have:

  • Access to the PingOne Remote MCP Server.

  • The remote server URL.

  • The required PingOne MCP Server system application set up.

  • PingOne administrator credentials.

  • An MCP-compatible client.

How it works

  1. You add the PingOne Remote MCP Server to your AI client.

  2. The client opens a browser window and sends you to PingOne to sign on.

  3. You sign on with your PingOne account and approve the connection.

  4. The client returns to the previous window and connects to the remote MCP server.

  5. You can begin using MCP tools from your client.

Reauthentication requirements depend on the administrator security settings in your environment.

Roles and access

All MCP tools adhere to the PingOne Roles and Permissions model. Admins can only access and use tools supported by their existing permissions.

  • The tools that appear in your client depend on the roles assigned to your administrator account. You must be assigned an administrator role to use PingOne tools.

    You must have the Environment Admin role or a custom role with permissions to view or edit the MCP settings page.

  • Assign the DaVinci Admin role to use DaVinci tools exposed through the remote MCP server.

  • If an administrator’s roles change, they must reconnect their MCP client to refresh the list of available tools.

  • Only the Environment Admin built-in role or a custom role with the adminMcp:update:settings permission can enable or disable MCP server tool access against any given environment.