---
title: Step 2. Configure connection properties
description: Explains how to configure the connection properties in the sample app for the Android OIDC sign-on module tutorial with PingAM.
component: orchsdks
page_id: orchsdks:oidc:try-it-out/android/pingam/02_configuring-connection-properties
canonical_url: https://developer.pingidentity.com/orchsdks/oidc/try-it-out/android/pingam/02_configuring-connection-properties.html
revdate: Thu, 2 Apr 2026 11:33:37 +0100
keywords: ["OAuth 2.0", "OpenID Connect", "Tutorial", "Source Code", "Integration", "SDK", "Android", "PingAM", "connection properties"]
---

# Step 2. Configure connection properties

[icon: circle-check, set=far]PingAM [icon: android, set=fab]Android

* [Prepare](00_before-you-begin.html)

* [Download](01_download-sample-repo.html)

* **Configure**

* [Run](03_test-the-app.html)

In this step, you configure the kotlin-oidc sample to connect to the OAuth 2.0 application you created in PingAM, using OIDC sign-on.

1. In Android Studio, open the `sdk-sample-apps/android/kotlin-oidc` project you cloned in the previous step.

2. In the Project pane, switch to the Android view.

3. In the Android view, navigate to **oidc > kotlin+java > com.pingidentity.samples.oidc.app**, and open `CentralizeLoginViewModel.kt`.

4. Locate the `OidcWebClient` object and update with the values from your PingAM tenant:

   ```kotlin
   val web by lazy {
       OidcWebClient {
           logger = Logger.STANDARD
           module(Oidc) {
               clientId = "sdkPublicClient"
               discoveryEndpoint = "https://openam.example.com:8443/openam/oauth2/realms/root/.well-known/openid-configuration"
               scopes = mutableSetOf("openid", "email", "address", "profile")
               redirectUri = "com.example.demo://oauth2redirect"
           }
       }
   }
   ```

   * *clientId*

     The client ID from your OAuth 2.0 application in PingAM.

     For example, `sdkPublicClient`

   * *discoveryEndpoint*

     The `.well-known` endpoint from your PingAM tenant.

     > **Collapse: How do I find my PingAM  URL?**
     >
     > To form the `.well-known` URL for an PingAM server, concatenate the following information into a single URL:
     >
     > 1. The base URL of the PingAM component of your deployment, including the port number and deployment path.
     >
     >    For example, `https://openam.example.com:8443/openam`
     >
     > 2. The string `/oauth2`
     >
     > 3. The hierarchy of the realm that contains the OAuth 2.0 client.
     >
     >    You must specify the entire hierarchy of the realm, starting at the Top Level Realm. Prefix each realm in the hierarchy with the `realms/` keyword.
     >
     >    For example, `/realms/root/realms/customers`
     >
     >    |   |                                                                                 |
     >    | - | ------------------------------------------------------------------------------- |
     >    |   | If you omit the realm hierarchy, the top level `ROOT` realm is used by default. |
     >
     > 4. The string `/.well-known/openid-configuration`
     >
     > For example, `https://openam.example.com:8443/openam/oauth2/realms/root/.well-known/openid-configuration`

   * *scopes*

     The scopes you added to your OAuth 2.0 application in PingAM.

     For example, `openid profile email address`

   * *redirectUri*

     The `redirect_uri` as configured in the OAuth 2.0 client profile.

     This value must exactly match a value configured in your OAuth 2.0 client.

     For example, `com.example.demo://oauth2redirect`

5. Save your changes.
