---
title: pingcli pingfederate oauth token-exchange token-generator-mappings apply
description: Create or update a token generator mapping
component: pingcli
version: 1.7
page_id: pingcli:command_reference:pingcli_pingfederate_oauth_token-exchange_token-generator-mappings_apply
canonical_url: https://developer.pingidentity.com/pingcli/1.7/command_reference/pingcli_pingfederate_oauth_token-exchange_token-generator-mappings_apply.html
llms_txt: https://developer.pingidentity.com/pingcli/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: September 3, 2026
section_ids:
  synopsis: Synopsis
  examples: Examples
  options: Options
  options-inherited-from-parent-commands: Options inherited from parent commands
  more-information: More information
---

# pingcli pingfederate oauth token-exchange token-generator-mappings apply

Create or update a token generator mapping

## Synopsis

Idempotently create or update a PingFederate token exchange processor policy to token generator mapping looked up by the "sourceId" and "targetId" fields in the JSON body. If no mapping for that pair exists it is created; if one exists it is updated.

```
pingcli pingfederate oauth token-exchange token-generator-mappings apply [flags]
```

## Examples

```
  # Create or update a token generator mapping (body supplies sourceId, targetId, and other fields)
  pingcli pingfederate oauth token-exchange token-generator-mappings apply --from-file token-generator-mapping.json

  # Read body from stdin
  pingcli pingfederate oauth token-exchange token-generator-mappings apply --from-file - < token-generator-mapping.json
```

## Options

```
  -f, --from-file string                             Path to a JSON file containing the request body, or "-" to read from stdin.
  -h, --help                                         help for apply
      --license-connection-group-assignment string   The license connection group
      --source-id string                             The ID of the Token Exchange Processor policy
      --target-id string                             The ID of the Token Generator
```

## Options inherited from parent commands

```
  -C, --config string           The relative or full path to a custom Ping CLI configuration file. (default $HOME/.pingcli/config.yaml)
  -D, --detailed-exitcode       Enable detailed exit code output. (default false) 0 - pingcli command succeeded with no errors or warnings. 1 - pingcli command failed with errors. 2 - pingcli command succeeded with warnings.
  -O, --output-format string    Specify the console output format. (default text) Options are: json, ndjson, ndjson-typed, ndjson-wrapped, text.
  -P, --profile string          The name of a configuration profile to use.
      --debug                   Enable debug output for error messages, including stack traces and transaction IDs. (default false)
      --log-file string         Write logs to a file at the given path. File logging is disabled when not set.
      --log-file-level string   Set the file log level. Options are: DEBUG, INFO, WARN, ERROR. (default DEBUG)
      --log-level string        Set the console log level. Options are: DEBUG, INFO, WARN, ERROR. (default WARN)
      --no-color                Disable text output in color. (default false)
      --query string            JMESPath expression to filter JSON output. Requires -O json, ndjson, ndjson-typed, or ndjson-wrapped. Example: --query 'data[?enabled].name'
```

## More information

* [pingcli pingfederate oauth token-exchange token-generator-mappings](pingcli_pingfederate_oauth_token-exchange_token-generator-mappings.html) - PingFederate Token Exchange Processor policy to Token Generator Mappings
