PingOne Platform APIs

PingOne Permissions by Identifier

A permission identifier is a three-part, colon-delimited string that represents the service, action, and resource to which the permission applies. The permission identifiers shown here are those for all PingOne services and resources, and are included in the response returned by calling Read All Built-in Admin Roles.

Custom role permission identifiers are included in the response returned by Read All Custom Admin Roles.

You’ll find these related tables useful when assigning admin roles:

The Special column indicates special handling of certain permissions:

  • Essential: Start building a new custom role with the minimum set of permissions needed for the role to be usable.

  • Sensitive: The permission either provides access to sensitive information, such as personal user data, or allows the bearer to perform important actions that could negatively impact the organization, such as deleting an environment.

The Endpoint column links to the API endpoint documentation page for each permission, where applicable.

Identifier Permission Special Endpoint

licensing:read:license

Read license information for the organization.

essential

Read All Licenses
Read One License
Read One License Name
Read Active Identity Counts by License

orgmgt:read:deployment

Read deployments for other Ping products in the PingOne environment. These other products might require additional configuration outside of PingOne.

essential

orgmgt:read:environment

Read a list of the environments that a user belongs to. Environments are the primary subdivision of an organization.

essential

Read One Bill of Materials
Read Organization Capabilities
Read Environment Capabilities
Read All Environments
Read One Environment
Read Active Identity Counts
Read Active Identity Counts by Date Range
Read Total Identity Counts

orgmgt:read:organization

Read the organization that a user belongs to. A user can belong to one organization only. The organization is the top-level identifier in PingOne.

essential

Read All Organizations
Read One Organization

admin:update:config

Update the administrator security settings used for accessing the admin console.

sensitive

Update Administrator Security (External IdP)
Update Administrator Security (Enhanced)
Update Administrator Security Populations (Hybrid)

adminMcp:update:settings

Update the administrator MCP settings used for managing the environment via AI agents.

sensitive

applications:issue:certificate

Issue a new KDC certificate

sensitive

applications:read:secret

Read the client secret for an application. Client secrets are used to authenticate an application with PingOne.

sensitive

Read Application Secret

applications:update:secret

Create a new client secret for an application. Client secrets are used to authenticate an application with PingOne.

sensitive

Update Application Secret

applications:delete:secret

Revoke the previous client secret for an application before it expires. Client secrets are used to authenticate an application with PingOne and can be revoked when a new secret is generated.

sensitive

Delete Previous Application Secret

certmgt:create:certificate

Create a certificate. Certificates are security credentials that PingOne uses for encryption and signing.

sensitive

Create Certificate with PKCS7 or PEM File
Import Certificate Authority (CA) Response to a CSR

certmgt:read:certificate

Read the metadata for a certificate and export the certificate as an X509 certificate. Certificates are security credentials that PingOne uses for encryption and signing.

sensitive

Get Certificates
Get Certificate
Get Certificate Applications
Export a Certificate Signing Request (CSR)

certmgt:update:certificate

Update a certificate. Updates include making a certificate default and reassigning a certificate to an application. Certificates are security credentials that PingOne uses for encryption and signing.

sensitive

certmgt:delete:certificate

Delete a certificate. Certificates are security credentials that PingOne uses for encryption and signing.

sensitive

Delete Certificate

certmgt:create:key

Create a new key pair. Key pairs are security credentials that PingOne uses for encryption and signing.

sensitive

Create Key
Create Key with PKCS12 File

certmgt:update:key

Update a key pair. Updates include making a key pair default and reassigning a key pair to an application. Key pairs are security credentials that PingOne uses for encryption and signing.

sensitive

Update Key

certmgt:delete:key

Delete a key pair. Key pairs are security credentials that PingOne uses for encryption and signing.

sensitive

Delete Key

dir:forceChange:userPassword

Force a user to change their password the next time they sign on. The password state is MUST_CHANGE_PASSWORD.

sensitive

Password Force Change

dir:recover:userPassword

Reset a user’s password using a recovery code. Send a recovery code.

sensitive

Password Recover
Password Resend Recovery Code

dir:reset:userPassword

Reset a user’s password without requiring a recovery code.

sensitive

dir:set:userPassword

Set a user’s clear text or pre-encoded password and set a user’s password authority.

sensitive

Update Password (Self)
Update Password (Admin)
Update Password (Set)
Update Password (Set Value)
Update Password (LDAP Gateway)

dir:unlock:userPassword

Unlock a user’s password. The password state is PASSWORD_LOCKED_OUT.

sensitive

Password Unlock

mfa:create:device

Create an MFA device.

sensitive

Create MFA User Device (Voice)
Create MFA User Device (Email)
Create MFA User Device (TOTP)
Create MFA User Device (FIDO2)
Create MFA User Device (SMS)
Create MFA User Device (OATH token)
Create MFA User Device (WhatsApp)
Create MFA User Device (PingID Desktop)
Create Remember Me Device

mfa:update:device

Update an MFA device.

sensitive

Unlock MFA User Device
Block MFA User Device
Activate MFA User Device
Activate MFA User Device (PingID Desktop)
Activate MFA User Device (OATH token)
Activate MFA User Device (FIDO2)
Resend Pairing Code
Send MFA Device Logs
Set Device Order
Unblock MFA User Device
Update Device Nickname

mfa:delete:device

Delete an MFA device.

sensitive

Delete MFA User Device
Remove Device Order

orgmgt:create:environment

Create an environment to include a set of services and capabilities. Define the name and description, and include license information. Environments are the primary subdivision of an organization.

sensitive

Create Environment

orgmgt:delete:environment

Delete an environment and all of its associated resources, such as applications, users, and branding. Environments are the primary subdivision of an organization.

sensitive

Delete Environment

permissions:update:applicationRoleAssignments

Assign or revoke admin roles for an application scope. Roles are used by worker applications only.

sensitive

permissions:update:gatewayRoleAssignments

Add roles and the associated permissions associated with a gateway scope. The gateway scope defines the attributes that can be accessed in the external LDAP directory.

sensitive

Create Gateway Role Assignments

permissions:delete:gatewayRoleAssignments

Remove roles and the associated permissions associated with a gateway scope. The gateway scope defines the attributes that can be accessed in the external LDAP directory.

sensitive

Delete Gateway Role Assignment

permissions:create:groupRoleAssignments

Assign an admin role to a group.

sensitive

Create Group Role Assignment

permissions:delete:groupRoleAssignments

Remove an admin role from a group.

sensitive

Delete Group Role Assignment

permissions:create:roles

Create a custom role for the environment.

sensitive

Create Custom Admin Role

permissions:read:roles

Read a list of custom roles for the environment.

sensitive

Read All Built-in Admin Roles
Read One Built-in Admin Role
Read All Custom Admin Roles
Read One Custom Admin Role

permissions:update:roles

Update the permissions that are included in a custom role for the environment.

sensitive

Update Custom Admin Role

permissions:delete:roles

Remove a custom role from the environment.

sensitive

Delete Custom Admin Role

permissions:update:userRoleAssignments

Update admin roles that are assigned to a user, including the role permissions.

sensitive

Create User Role Assignment
Delete User’s Role Assignment

promotion:create:promotion

Start the promotion of configuration details from one environment to another. This permission is required in the source environment and 'Execute promotion' is required in the target environment.

sensitive

promotion:execute:promotion

Promote the environment resource configuration from one environment to another. This permission is required in the target environment and 'Create promotion' is required in the source environment.

sensitive

promotion:read:promotion

Read environment promotion details, such as which environment resources were promoted from one environment to another.

sensitive

promotion:delete:promotion

Cancel an in-progress environment promotion. Environment promotions are the transfer of configuration details from one environment to another.

sensitive

promotion:read:promotionConfiguration

Read environment-specific configuration data for promotion. Environment promotion ensures the smooth transition of configuration data between environments.

sensitive

promotion:update:promotionConfiguration

Create or update environment-specific configuration data for promotion. Environment promotion ensures the smooth transition of configuration data between environments.

sensitive

promotion:create:promotionVariable

Create environment promotion variables. Promotion variables are used to define attributes that must have different values in different environments.

sensitive

promotion:read:promotionVariable

Read environment promotion variables. Promotion variables are used to define attributes that must have different values in different environments.

sensitive

promotion:update:promotionVariable

Update the values of promotion variables. Promotion variables are used to define attributes that must have different values in different environments.

sensitive

promotion:delete:promotionVariable

Delete environment promotion variables. Promotion variables are used to define attributes that must have different values in different environments.

sensitive

promotion:create:snapshot

Create snapshots of environment resources. A snapshot is a record of the configuration for the asset at a specific point in time.

sensitive

promotion:read:snapshot

Read snapshots of environment resources. A snapshot is a record of the configuration for the resource at a specific point in time.

sensitive

promotion:update:snapshot

Update snapshots of environment resources. A snapshot is a record of the configuration for the resource at a specific point in time.

sensitive

promotion:delete:snapshot

Delete snapshots of environment resources. A snapshot is a record of the configuration for the resource at a specific point in time.

sensitive

resources:read:secret

Read the client secret for a resource. Client secrets are used to authenticate a resource with PingOne.

sensitive

Read Resource Client Secret

resources:update:secret

Create a new client secret for a resource. Client secrets are used to authenticate a resource with PingOne.

sensitive

Create Resource Client Secret

resources:delete:secret

Revoke the previous client secret for an application resource before it expires. Client secrets are used to authenticate a resource with PingOne and can be revoked when a new secret is generated.

sensitive

Delete Previous Resource Client Secret

admin:read:config

Read the administrator security settings used for accessing the admin console.

Read Administrator Security
Read Administrator Security Populations

adminMcp:read:settings

Read the administrator MCP settings used for managing the environment via AI agents.

agreements:create:agreement

Create an agreement that users must consent to as part of an authentication policy or flow.

Create Agreement
Create Revision

agreements:read:agreement

Read agreements that users must consent to as part of an authentication policy or flow.

Read All Agreements
Read One Agreement
Read All Revisions
Read One Revision

agreements:update:agreement

Update an agreement that users must consent to as part of an authentication policy or flow.

Update Agreement

agreements:delete:agreement

Delete an agreement that users must consent to as part of an authentication policy or flow.

Delete Agreement
Delete Revision

agreements:create:oauthConsent

Create a record of the user’s consent to share their information with an OAuth application during an authentication flow.

Record User OAuth Scope Consent

agreements:read:oauthConsent

Read the OAuth consent history for a user.

Read All User OAuth Scope Consents
Read One User OAuth Scope Consent

agreements:update:oauthConsent

Update the recorded date for the user’s consent to an OAuth application request for personal information during an authentication flow.

Revoke User OAuth Scope Consent

agreements:create:userConsent

Consent to an agreement on behalf of a particular user.

Accept Agreement

agreements:read:userConsent

Read the consent history for a user, including agreement names, language, and date of consent.

Read All User Agreement Consents
Read One User Agreement Consent

agreements:update:userConsent

Require a user to re-consent to an agreement when the agreement has been updated.

agreements:delete:userConsent

Delete consent to an agreement on behalf of a particular user.

Revoke Agreement

alerting:create:channel

Create an alert channel to define the types of events that will trigger an alert and to list email addresses where the alerts will be sent.

Create Alert Channel (Email)

alerting:read:channel

Read alert channels to view the types of events that will trigger an alert and the list of email addresses where the alerts will be sent.

Read All Alert Channels per Environment

alerting:update:channel

Update an alert channel to change the types of events that will trigger an alert or to change the email addresses where the alerts will be sent.

Update Alert Channel

alerting:delete:channel

Delete an alert channel to stop sending alerts about events to a list of email addresses.

Delete Alert Channel

applicationRoles:read:applicationEntitlement

Query a user’s entitled application permissions, which control the actions the user can take in applications and APIs. Application permissions are defined on resources and assigned through application roles.

applicationRoles:create:applicationPermission

Create permissions that represent actions that can be taken on resources in external applications.

Create Application Permissions

applicationRoles:read:applicationPermission

List application permissions and read permission details, including permission descriptions, actions, and resources.

Read Application Permissions
Read One Application Permission

applicationRoles:update:applicationPermission

Update details for application permissions, including permission actions and descriptions.

Update Application Permission

applicationRoles:delete:applicationPermission

Delete application permissions.

Delete Application Permission

applicationRoles:create:applicationResource

Create resources that represent protected features in external applications.

applicationRoles:read:applicationResource

List application resources and read resource details, including resource names and descriptions.

Read Application Resources
Read One Application Resource

applicationRoles:update:applicationResource

Update details for application resources, including resource names and descriptions.

applicationRoles:delete:applicationResource

Delete application resources.

applicationRoles:create:applicationRole

Create roles that group permissions for external applications by function.

Create Application Role

applicationRoles:read:applicationRole

List application roles and read role details, including role names and descriptions.

Read Application Roles
Read One Application Role

applicationRoles:update:applicationRole

Update details for application roles, including role names and descriptions.

Update Application Role

applicationRoles:delete:applicationRole

Delete application roles.

Delete Application Role

applicationRoles:create:applicationRoleAssignment

Assign application roles to users to grant the associated permissions for actions in external applications.

Create Application Role Assignments
Create User Application Role Assignment

applicationRoles:read:applicationRoleAssignment

Read application roles that are assigned to a user, including the role permissions.

Read Application Role Assignments
Read One Application Role Assignment
Read User Application Role Assignments
Read Application Role Assignments by Role
Read Application Role Users
Read One Application Role User

applicationRoles:delete:applicationRoleAssignment

Remove application role assignments from users to revoke the associated permissions for actions in external applications.

Delete Application Role Assignment
Delete User Application Role Assignment

applicationRoles:create:applicationRoleEntry

Add permissions for external applications to application roles.

Create Application Role Permission

applicationRoles:read:applicationRoleEntry

List permissions for an application role.

Read Application Role Permissions

applicationRoles:delete:applicationRoleEntry

Delete permissions from application roles.

Delete Application Role Permission

applications:create:application

Create an application in the environment.

Create Application (OIDC Protocol - Web App)
Create Application (OIDC Protocol - Native App)
Create Application (OIDC Protocol - Single Page App)
Create Application (OIDC Protocol - Service App)
Create Application (OIDC Protocol - AI Agent App)
Create Application (OIDC Protocol - Worker App)
Create Application (OIDC Protocol - Worker Interactive App)
Create Application (OIDC Protocol - PingFederate Worker App)
Create Application (OIDC Device Authorization Grant)
Create Application (OIDC Mobile App)
Create Application (SAML Protocol)
Create Application (SAML Protocol) - XML Metadata
Create Application (SAML Protocol) - URL Metadata
Create Application (WS-Federation Protocol)
Create Application Attribute Mapping

applications:read:application

Read the settings for an application in the environment.

Read All Applications
Read One Application
Read Application Metadata
Read All Application Attribute Mappings
Read One Application Attribute Mapping
Read Device Requirements

applications:update:application

Update the settings for an application in the environment.

Update Application (OIDC)
Update Application (SAML)
Update Application (WS-Federation)
Update Application (PingID App)
Update Application Metadata
Update Application Attribute Mapping
Update Device Requirements

applications:delete:application

Delete an application from the environment.

Delete Application
Delete Application Attribute Mapping
Delete Device Requirements

applications:create:flowPolicyAssignment

Assign DaVinci policies to PingOne applications. When assigned, a DaVinci policy controls which DaVinci flow a PingOne application uses for authentication.

Create an Application Flow Policy Assignment

applications:read:flowPolicyAssignment

Read the assigned DaVinci policies for any PingOne application.

Read All Application Flow Policy Assignments
Read One Application Flow Policy Assignment

applications:update:flowPolicyAssignment

Update the policy order for DaVinci policies assigned to PingOne applications. A PingOne application applies policies in their listed order from top to bottom.

Update an Application Flow Policy Assignment

applications:delete:flowPolicyAssignment

Unassign DaVinci policies from PingOne applications. When unassigned, a DaVinci policy no longer has control over the authentication experience for the PingOne application.

Delete an Application Flow Policy Assignment

applications:create:grant

Assign a resource scope to an application. Resource scopes define application access to user details, such as name and email address.

Create Grant

applications:read:grant

Read the resource scope that is assigned to an application. Resource scopes define application access to user details, such as name and email address.

Read All Grants for an Application
Read One Grant for an Application

applications:update:grant

Change the resource scopes that are assigned to an application. Resource scopes define application access to user details, such as name and email address.

Update Grant

applications:delete:grant

Delete an assigned resource scope from an application. Resource scopes define application access to user details, such as name and email address.

Delete Grant

applications:create:pushCredentials

Create push credentials for a mobile application.

Create MFA Push Credential (APNS)
Create MFA Push Credential (FCM_HTTP_V1)
Create MFA Push Credential (HMS)

applications:read:pushCredentials

Read push credentials for a mobile application.

Read All MFA Push Credentials
Read One MFA Push Credential

applications:update:pushCredentials

Update push credentials for a mobile application.

Update MFA Push Credential

applications:delete:pushCredentials

Delete push credentials for a mobile application.

Delete MFA Push Credential

applications:create:signOnPolicyAssignment

Assign an authentication policy that defines the sign-on requirements used to access an application.

Create SOP Assignment

applications:read:signOnPolicyAssignment

Read authentication policies that are assigned to an application. Authentication policies define the sign-on requirements used to access an application.

Read All SOP Assignments
Read One SOP Assignment

applications:update:signOnPolicyAssignment

Update the authentication policy that is assigned to an application to change the sign-on requirements used to access an application.

Update SOP Assignment

applications:delete:signOnPolicyAssignment

Delete an assigned authentication policy from an application. Authentication policies define the sign-on requirements used to access an application.

Delete SOP Assignment

audit_reporting:read:activity

Access to the audit report and event content including PII; ability to request older event data from storage.

Restore Activities
Read Audit Activities
Read Activity Resources
Read Audit Activities
Read One Audit Activity
Read Authentications Per Application
Read Authentications Per Application (Partial)
Read User Activities

authn:create:sessions

Create a session for a user when they complete authentication during sign-on.

Reset Authentication Session by Session ID
Reset Authentication Session by Session Token

authn:read:sessions

Read all sessions for a particular user.

Read Session By ID
Read Session By Session Token
Read All Sessions
Read One Session

authn:update:sessions

Update a user session when the authentication process or API request has a valid session ID cookie.

Update Session By ID
Update Session By Session Token

authn:delete:sessions

Delete a recent user session to sign the user out of PingOne. For example, you can delete a session if you detect suspicious activity.

Delete Session By ID
Delete Session By Session Token
Delete Session

authn:create:signOnPolicy

Create an authentication policy, which defines how user identities are verified at sign-on.

Create Sign-On Policy
Create Sign-On Policy Action (LOGIN)
Create Sign-On Policy Action (MFA)
Create Sign-On Policy Action (IDENTIFIER_FIRST)
Create Sign-On Policy Action (PROGRESSIVE_PROFILING)
Create Sign-On Policy Action (AGREEMENT)
Create Sign-On Policy Action (IDENTITY_PROVIDER)

authn:read:signOnPolicy

Read authentication policies, which define how user identities are verified at sign-on.

Read All Sign-On Policies
Read One Sign-On Policy
Read All Sign-On Policy Actions
Read One Sign-On Policy Action

authn:update:signOnPolicy

Update an authentication policy to change how user identities are verified at sign-on.

Update Sign-On Policy
Update Sign-On Policy Action

authn:delete:signOnPolicy

Delete an authentication policy.

Delete Sign-On Policy
Delete Sign-On Policy Action

authz:create:adaptiveTrustPolicy

Create an adaptive access policy. Adaptive access policies define contextual rules for access to applications.

authz:read:adaptiveTrustPolicy

Read configuration details for adaptive access policies. Adaptive access policies define contextual rules for access to applications.

authz:update:adaptiveTrustPolicy

Update an adaptive access policy. Adaptive access policies define contextual rules for access to applications.

authz:delete:adaptiveTrustPolicy

Delete an adaptive access policy. Adaptive access policies define contextual rules for access to applications.

authz:create:adaptiveTrustPolicyAssignment

Assign an adaptive access policy to an application. Adaptive access policies define contextual rules for access to applications.

authz:read:adaptiveTrustPolicyAssignment

Read adaptive access policy assignments for an application. Policy assignments control which policies the application uses for adaptive access.

authz:delete:adaptiveTrustPolicyAssignment

Delete adaptive access policy assignments from an application. Policy assignments control which policies the application uses for adaptive access.

authz:create:apiServer

Create an API service and associated operations, which represent an HTTP API with access control handled by PingOne Authorize.

Create API Service

authz:read:apiServer

Read details for an API service and its associated operations, including the name, base URLs, and directory and token source.

Read API Services
Read One API Service

authz:update:apiServer

Update details for an API service and its associated operations, including the name, base URLs, and basic rules.

Update API Service

authz:delete:apiServer

Delete an API service and its associated operations, decision endpoint, and policy tree.

Delete API Service

authz:deploy:apiServerDeployment

Deploy API service configuration updates and policies to the API service’s decision endpoint.

Deploy API Service

authz:read:apiServerDeployment

Read an API service’s deployment status.

Retrieve Deployment Status

authz:create:authorizationAttribute

Create an authorization attribute in the Trust Framework. Authorization attributes provide contextual information used in authorization decisions.

authz:read:authorizationAttribute

Read configuration details for authorization attributes in the Trust Framework. Authorization attributes provide contextual information used in authorization decisions.

authz:test:authorizationAttribute

Test an authorization attribute in the Trust Framework. Authorization attributes provide contextual information used in authorization decisions.

authz:update:authorizationAttribute

Update an authorization attribute in the Trust Framework. Authorization attributes provide contextual information used in authorization decisions.

authz:delete:authorizationAttribute

Delete an authorization attribute from the Trust Framework. Authorization attributes provide contextual information used in authorization decisions.

authz:create:authorizationCondition

Create an authorization condition in the Trust Framework. Authorization conditions use comparisons to define authorization policy logic.

authz:read:authorizationCondition

Read configuration details for authorization conditions in the Trust Framework. Authorization conditions use comparisons to define authorization policy logic.

authz:test:authorizationCondition

Test an authorization condition in the Trust Framework. Authorization conditions use comparisons to define authorization policy logic.

authz:update:authorizationCondition

Update an authorization condition in the Trust Framework. Authorization conditions use comparisons to define authorization policy logic.

authz:delete:authorizationCondition

Delete an authorization condition from the Trust Framework. Authorization conditions use comparisons to define authorization policy logic.

authz:create:authorizationModule

Create an authorization module. Authorization modules are subdivisions of an environment that contain their own distinct Trust Framework and set of policies, allowing teams to work independently.

authz:read:authorizationModule

Read an authorization module. Authorization modules are subdivisions of an environment that contain their own distinct Trust Framework and set of policies, allowing teams to work independently.

authz:update:authorizationModule

Update an authorization module. Authorization modules are subdivisions of an environment that contain their own distinct Trust Framework and set of policies, allowing teams to work independently.

authz:delete:authorizationModule

Delete an authorization module. Authorization modules are subdivisions of an environment that contain their own distinct Trust Framework and set of policies, allowing teams to work independently.

authz:create:authorizationPolicy

Create an authorization policy. Authorization policies define the context and logic used to control access to application resources.

authz:read:authorizationPolicy

Read configuration details for authorization policies. Authorization policies define the context and logic used to control access to application resources.

authz:test:authorizationPolicy

Test an authorization policy. Authorization policies define the context and logic used to control access to application resources.

authz:update:authorizationPolicy

Update an authorization policy. Authorization policies define the context and logic used to control access to application resources.

authz:delete:authorizationPolicy

Delete an authorization policy. Authorization policies define the context and logic used to control access to application resources.

authz:create:authorizationProcessor

Create an authorization processor in the Trust Framework. Authorization processors transform data returned from authorization attributes and services.

authz:read:authorizationProcessor

Read configuration details for authorization processors in the Trust Framework. Authorization processors transform data returned from authorization attributes and services.

authz:update:authorizationProcessor

Update an authorization processor in the Trust Framework. Authorization processors transform data returned from authorization attributes and services.

authz:delete:authorizationProcessor

Delete an authorization processor from the Trust Framework. Authorization processors transform data returned from authorization attributes and services.

authz:create:authorizationRule

Create an authorization rule. Authorization rules use conditions or in-line comparisons to define authorization policy logic.

authz:read:authorizationRule

Read configuration details for authorization rules. Authorization rules use conditions or in-line comparisons to define authorization policy logic.

authz:test:authorizationRule

Test an authorization rule. Authorization rules use conditions or in-line comparisons to define authorization policy logic.

authz:update:authorizationRule

Update an authorization rule. Authorization rules use conditions or in-line comparisons to define authorization policy logic.

authz:delete:authorizationRule

Delete an authorization rule. Authorization rules use conditions or in-line comparisons to define authorization policy logic.

authz:create:authorizationService

Create an authorization service in the Trust Framework. Authorization services connect to data sources used in authorization decisions.

authz:read:authorizationService

Read configuration details for authorization services in the Trust Framework. Authorization services connect to data sources used in authorization decisions.

authz:test:authorizationService

Test an authorization service in the Trust Framework. Authorization services connect to data sources used in authorization decisions.

authz:update:authorizationService

Update an authorization service in the Trust Framework. Authorization services connect to data sources used in authorization decisions.

authz:delete:authorizationService

Delete an authorization service from the Trust Framework. Authorization services connect to data sources used in authorization decisions.

authz:create:authorizationStatement

Create an authorization statement. Authorization statements provide additional processing instructions in authorization decisions.

authz:read:authorizationStatement

Read configuration details for authorization statements. Authorization statements provide additional processing instructions in authorization decisions.

authz:update:authorizationStatement

Update an authorization statement. Authorization statements provide additional processing instructions in authorization decisions.

authz:delete:authorizationStatement

Delete an authorization statement. Authorization statements provide additional processing instructions in authorization decisions.

authz:read:authorizeDeployment

Read deployment details for an Authorize gateway, including the policy version and minimum supported gateway instance version.

authz:authorize:decisionendpoint

Make a decision request to a decision endpoint, initiating evaluation of policies deployed to the endpoint.

Evaluate a Decision Request
Evaluate a Bulk Decision Request

authz:create:decisionendpoint

Create a decision endpoint, which provides an environment for authorization policy deployment.

Create Decision Endpoint

authz:read:decisionendpoint

Read details for a decision endpoint, including its name, description, policy version deployed, and whether recent decisions are recorded.

Read All Decision Endpoints
Read One Decision Endpoint

authz:update:decisionendpoint

Update details for a decision endpoint, including its name, description, policy version deployed, and whether recent decisions are recorded.

Update Decision Endpoint

authz:delete:decisionendpoint

Delete a decision endpoint and any recent decisions stored for the endpoint.

Delete Decision Endpoint

authz:read:deploymentpackage

Read the deployment package of policies and Trust Framework definitions associated with a specific authorization version.

authz:create:entity

Create an authorization service, attribute, condition, processor, policy set, policy, rule, statement, or target.

authz:read:entity

Read details about an authorization service, attribute, condition, processor, policy set, policy, rule, statement, or target.

authz:test:entity

Test an authorization service, attribute, condition, policy set, policy, or library rule.

authz:update:entity

Update an authorization service, attribute, condition, processor, policy set, policy, rule, statement, or target.

authz:delete:entity

Delete an authorization service, attribute, condition, processor, policy set, policy, rule, statement, or target.

authz:create:externalOAuthServer

Create external OAuth servers. These issuers for access tokens generated outside of PingOne are used in conjunction with API services in PingOne Authorize to control access to APIs.

Create External OAuth Server

authz:read:externalOAuthServer

Read details for external OAuth servers. These issuers for access tokens generated outside of PingOne are used in conjunction with API services in PingOne Authorize to control access to APIs.

Read All External OAuth Servers
Read One External OAuth Server

authz:update:externalOAuthServer

Update external OAuth servers. These issuers for access tokens generated outside of PingOne are used in conjunction with API services in PingOne Authorize to control access to APIs.

Update External OAuth Server

authz:delete:externalOAuthServer

Delete external OAuth servers. These issuers for access tokens generated outside of PingOne are used in conjunction with API services in PingOne Authorize to control access to APIs.

Delete External OAuth Server

authz:read:recentdecisions

Read details about the decision flow and elements used in recent decisions for a decision endpoint.

Read One Recent Decision
Read Recent Decisions

authz:read:tag

Read an authorization version name.

authz:update:tag

Create or update an authorization version name.

authz:delete:tag

Delete an authorization version name.

authz:read:version

Read details about an authorization version, including the entity that changed, the date and time, and the user who made the change.

bootstrap:create:bootstrap

Start a bootstrap execution for provisioning.

bootstrap:read:bootstrap

Check bootstrap execution status by invoking the GET endpoint.

branding:update:branding

Create and update branding

branding:delete:branding

Delete branding

branding:read:brandingSettings

Read the company name and logo for an environment.

Read Branding Settings

branding:update:brandingSettings

Update the company name and logo for an environment.

Update Branding Settings

branding:create:customDomain

Create a custom domain for the environment to personalize the user-facing PingOne service URLs.

Create Domain
Verify Domain
Import Certificate

branding:read:customDomain

Read the custom domain for the environment and see the corresponding custom service URLs. If enabled, custom domains replace pingone in the address bar.

Read All Domains
Read One Domain

branding:update:customDomain

Update the custom domain for the environment to renew the SSL certificate.

Update Domain

branding:delete:customDomain

Delete a custom domain from the environment to stop using it in the user-facing PingOne service URLs.

Delete Domain

branding:create:theme

Create a theme to customize the colors and images used on your registration pages, sign-on pages, and verification pages for an environment.

Create Branding Theme
Migrate Branding Theme
Clone Branding Theme (Deprecated)

branding:read:theme

Read the themes available for an environment. Themes dictate the colors and images used on the registration pages, sign-on pages, and verification pages for an environment.

Read Branding Themes
Read One Branding Theme
Read Branding Theme Default

branding:update:theme

Update a theme in an environment. Themes dictate the colors and images used on the registration pages, sign-on pages, and verification pages for an environment.

Update Branding Theme
Update Branding Theme Default

branding:delete:theme

Delete a theme from an environment. Themes dictate the customization of the colors and images used on the registration pages, sign-on pages, and verification pages for an environment.

Delete Branding Theme

certmgt:read:key

Read the metadata for a key pair and download it as an X509 certificate. Key pairs are security credentials that PingOne uses for encryption and signing.

Get Keys
Get Key
Get Key Applications
Export Public Key (PKCS7 DER)
Export Public Key (X509 PEM)

certmgt:create:krp

Create a new key rotation policy in the environment. PingOne uses key rotation to automatically generate new cryptographic keys at a particular interval.

Create Key Rotation Policy

certmgt:read:krp

Read a list of key rotation policies in the environment. PingOne uses key rotation to automatically generate new cryptographic keys at a particular interval.

Get Key Rotation Policies
Get JWKS for Key Rotation Policy

certmgt:update:krp

Update a key rotation policy in the environment. PingOne uses key rotation to automatically generate new cryptographic keys at a particular interval.

Update Key Rotation Policy

certmgt:delete:krp

Delete a key rotation policy from the environment. PingOne uses key rotation to automatically generate new cryptographic keys at a particular interval.

Delete Key Rotation Policy

console:display:environmentOverview

View the environment overview page in the administrator console. This permission only affects visibility in the administrator console and not API access.

console:display:environmentProperties

View the environment properties page in the administrator console. This permission only affects visibility in the administrator console and not API access.

credentialsIssuance:create:credentialSigningKey

Create a credential signing key for an environment. Credential signing keys sign a verifiable credential using a customer-provided service.

Create Customer Signing Public Key

credentialsIssuance:read:credentialSigningKey

Read a credential signing key for an environment. Credential signing keys sign a verifiable credential using a customer-provided service.

Read All Customer Signing Public Keys
Read One Customer Signing Public Key

credentialsIssuance:update:credentialSigningKey

Update a credential signing key for an environment. Credential signing keys sign a verifiable credential using a customer-provided service.

Update Customer Signing Public Key

credentialsIssuance:delete:credentialSigningKey

Delete a credential signing key for an environment. Credential signing keys sign a verifiable credential using a customer-provided service.

Delete Customer Signing Public Key

credentialsIssuance:create:credentialType

Create a credential type for an environment. A credential type defines a template that is used when creating or updating a user credential.

Create Credential Type (automated)
Create Credential Type (managed)

credentialsIssuance:read:credentialType

Read a credential type for an environment. A credential type defines a template that is used when creating or updating a user credential.

Read All Credential Types
Read One Credential Type
Read All Credential Type Versions
Read One Credential Type Version

credentialsIssuance:update:credentialType

Update a credential type for an environment. A credential type defines a template that is used when creating or updating a user credential.

Update a Credential Type

credentialsIssuance:delete:credentialType

Delete a credential type for an environment. A credential type defines a template that is used when creating or updating a user credential.

Delete a Credential Type

credentialsIssuance:create:credentials

Create a credential. Credentials allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Create a User Credential

credentialsIssuance:read:credentials

Read a credential. Credentials allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation..

Read All User Credentials
Read One User Credential
Read One User Credential Wallets
Read One User Credential One Wallet
Read One Digital Wallet Credentials

credentialsIssuance:update:credentials

Update a credential. Credentials allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Update a User Credential
Revoke a User Credential

credentialsIssuance:delete:credentials

Delete a credential. Credentials allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Delete a User Credential

credentialsIssuance:create:digitalWallet

Create a digital wallet for a user. A digital wallet links an instance of a digital wallet application to a user.

Create Digital Wallet

credentialsIssuance:read:digitalWallet

Read a digital wallet for a user. A digital wallet links an instance of a digital wallet application to a user.

Read All Digital Wallets
Read One Digital Wallet

credentialsIssuance:update:digitalWallet

Updated a digital wallet for a user. A digital wallet links an instance of a digital wallet application to a user.

Update Digital Wallet

credentialsIssuance:delete:digitalWallet

Delete a digital wallet for a user. A digital wallet links an instance of a digital wallet application to a user.

Delete Digital Wallet

credentialsIssuance:create:digitalWalletApplication

Create a digital wallet application. A digital wallet application defines the relationship between a user’s digital wallet and a customer’s PingOne application.

Create Digital Wallet App

credentialsIssuance:read:digitalWalletApplication

Read a digital wallet application. A digital wallet application defines the relationship between a user’s digital wallet and a customer’s PingOne application.

Read All Digital Wallet Apps
Read One Digital Wallet App

credentialsIssuance:update:digitalWalletApplication

Update a digital wallet application. A digital wallet application defines the relationship between a user’s digital wallet and a customer’s PingOne application.

Update Digital Wallet App

credentialsIssuance:delete:digitalWalletApplication

Delete a digital wallet application. A digital wallet application defines the relationship between a user’s digital wallet and a customer’s PingOne application.

Delete Digital Wallet App

credentialsIssuance:create:issuanceRule

Create an issuance rule for a credential type. Issuance rules are used to issue credentials to a specified group, population or SCIM filter.

Create Credential Issuance Rule

credentialsIssuance:read:issuanceRule

Read an issuance rule for a credential type. Issuance rules are used to issue credentials to a specified group, population or SCIM filter.

Read All Credential Issuance Rules
Read One Credential Issuance Rule
Read Credential Issuance Rule Usage Counts
Read Credential Issuance Rule Usage Details

credentialsIssuance:update:issuanceRule

Update an issuance rule for a credential type. Issuance rules are used to issue credentials to a specified group, population or SCIM filter.

Update Credential Issuance Rule

credentialsIssuance:delete:issuanceRule

Delete an issuance rule for a credential type. Issuance rules are used to issue credentials to a specified group, population or SCIM filter.

Delete Credential Issuance Rule

credentialsIssuance:create:issuerProfile

Create the environment profile used for issuing user credentials.

credentialsIssuance:read:issuerProfile

Read the environment profile used for issuing user credentials.

Read Credential Issuer Profile

credentialsIssuance:update:issuerProfile

Update the environment profile used for issuing user credentials.

Update Credential Issuer Profile

credentialsIssuance:create:openid4vciOffer

Create an OpenID for Verifiable Credential Issuance (OpenID4VCI) offer. An OpenID4VCI offer allows end users to securely receive verifiable credentials from an issuer.

Initiate OpenID4VCI Offer

credentialsIssuance:read:openid4vciOffer

Read an OpenID for Verifiable Credential Issuance (OpenID4VCI) offer. An OpenID4VCI offer allows end users to securely receive verifiable credentials from an issuer.

Read One OpenID4VCI Offer

credentialsIssuance:read:stagedChanges

Read staged changes for an issuance rule. Staged changes show actions for an issuance rule that are staged for execution.

Read All Credential Issuance Rule Staged Changes
Read One Credential Issuance Rule Staged Change

credentialsIssuance:update:stagedChanges

Update staged changes for an issuance rule. Allows for refreshing and applying of staged actions for an issuance rule.

Apply Credential Issuance Rule Staged Changes

credentialsVerification:create:presentationSession

Create a Verification Session. Verification Sessions allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Create Credential Verification Session (NATIVE)
Create Credential Verification Session (NATIVE - Push Notification)
Create Credential Verification Session (OPENID4VP)

credentialsVerification:read:presentationSession

Read a Verification Session. Verification Sessions allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Read Credential Verification Credential Data
Read Credential Verification Session Data
Read One Credential Verification Status

credentialsVerification:delete:presentationSession

Delete a Verification Session. Verification Sessions allow providers of services to verify authenticity and accuracy of issuance and data integrity at the time of presentation.

Delete Credential Verification Session

davinci:create:applications

Create DaVinci applications

Create DaVinci Application

davinci:read:applications

Read DaVinci applications

Read DaVinci Applications
Read One DaVinci Application

davinci:update:applications

Update DaVinci applications

Rotate DaVinci Application Key
Rotate DaVinci Application Secret
Update DaVinci Application

davinci:delete:applications

Delete DaVinci applications

Delete DaVinci Application

davinci:create:connections

Create a new DaVinci connector for an environment and make it available for use in all DaVinci flows.

Create DaVinci Connector Instance
Clone DaVinci Connector Instance

davinci:read:connections

Read a list of all connectors added to an environment, including their configurations and containing DaVinci flows.

Read All DaVinci Connector Instances
Read One DaVinci Connector Instance

davinci:update:connections

Update the environment-level configuration of a connector instance. These changes also affect any use of the connector in DaVinci flows.

Update DaVinci Connector Instance

davinci:delete:connections

Delete a connector instance from an environment. This operation renders the connector instance non-functional in DaVinci flows.

Delete DaVinci Connector Instance

davinci:read:connectors

Read DaVinci connectors

Read All DaVinci Connectors
Read One DaVinci Connector
Read DaVinci Connector Details

davinci:create:constructs

Create variables of any available scope in an environment or using the Variables connector in a DaVinci flow.

Create DaVinci Variable

davinci:read:constructs

Read all variables and their values across the environment and within DaVinci flows.

Read All DaVinci Variables
Read One DaVinci Variable

davinci:update:constructs

Update any variables across the environment and within DaVinci flows.

Update DaVinci Variable

davinci:delete:constructs

Delete any variables across the environment and within DaVinci flows.

Delete DaVinci Variable

davinci:create:dvFlows

Create or import DaVinci flows in one or more environments. Add new connectors during the import process.

Create DaVinci Flow
Deploy a DaVinci Flow
Clone a DaVinci Flow
Import DaVinci Flow
Import DaVinci Legacy Flow

davinci:deploy:dvFlows

Publish versions of DaVinci flows to make them available for use in DaVinci applications.

davinci:read:dvFlows

Read all DaVinci flows and their internal configurations. Also allows you to export flows.

Read One DaVinci Flow
Read All DaVinci Flows

davinci:update:dvFlows

Update the configuration and design of DaVinci flows and add, configure, or remove their subcomponents at the flow level.

Enable a DaVinci Flow
Update DaVinci Flow

davinci:delete:dvFlows

Delete existing DaVinci flows.

Delete DaVinci Flow

davinci:read:dvUsers

Read DaVinci users. DaVinci users are end users created during a DaVinci flow and stored in DaVinci.

davinci:update:dvUsers

Update users in DaVinci. DaVinci users are end users created during a DaVinci flow and stored in DaVinci.

davinci:delete:dvUsers

Delete users from DaVinci. DaVinci users are end users created during a DaVinci flow and stored in DaVinci.

davinci:read:events

Read auditing information for the admin portal. This includes all events that generate an audit log entry, including the creation or modification of a flow, flow policy, or connector.

davinci:create:flowPolicies

Create DaVinci flow policies

Create DaVinci Application Flow Policies

davinci:read:flowPolicies

Read DaVinci flow policies

Read DaVinci Application Flow Policies
Read DaVinci Application Flow Policy Events
Read One DaVinci Application Flow Policy

davinci:update:flowPolicies

Update DaVinci flow policies

Update DaVinci Application Flow Policy

davinci:delete:flowPolicies

Delete DaVinci flow policies

Delete DaVinci Application Flow Policy

davinci:export:flowVersions

Export DaVinci flow versions

Export a DaVinci Flow Version

davinci:read:flowVersions

Read DaVinci flow versions

Read All DaVinci Flow Versions
Read One DaVinci Flow Version
Read DaVinci Flow Version Details

davinci:revert:flowVersions

Revert DaVinci flow versions

Revert DaVinci Flow Version

davinci:update:flowVersions

Update DaVinci flow versions

Add a DaVinci Flow Version Alias

davinci:delete:flowVersions

Delete DaVinci flow versions

Delete DaVinci Flow Version

davinci:read:interactionEvents

Read DaVinci flow analytics. Flow analytics display information about flow executions, including the nodes used, inputs, and outputs.

davinci:read:outcomeEvents

Read outcome events generated by flow analytics connectors. Outcome events contain developer-defined statuses to track specific user journeys.

davinci:read:settings

Read DaVinci company settings, including debug log and staggered flow execution settings.

davinci:update:settings

Update DaVinci company settings, including debug log and staggered flow execution settings.

davinci:read:stats

Read administrator statistics about the admin portal. This includes the UI dashboard summary and data about the creation and use of flows, connectors, variables, and users.

davinci:create:uiTemplates

Create user interface templates in DaVinci. UI templates can be used in a DaVinci flow to match your company style and branding.

Create DaVinci UI Template

davinci:read:uiTemplates

Read user interface templates in DaVinci. UI templates can be used in DaVinci flows to match your company style and branding.

Read DaVinci UI Templates
Read One DaVinci UI Template

davinci:update:uiTemplates

Update user interface templates in DaVinci. UI templates can be used in DaVinci flows to match your company style and branding.

davinci:delete:uiTemplates

Delete user interface templates from DaVinci. The UI template can no longer be used in DaVinci flows.

Delete DaVinci UI Template

devices:create:seenDevice

Create/Update accessing device

devices:read:seenDevice

Read accessing device

devices:update:seenDevice

Update accessing device

devices:delete:seenDevice

Delete accessing device

devices:create:userSeenDevice

Create user association with accessing device

devices:read:userSeenDevice

Read user association with accessing device

devices:update:userSeenDevice

Update user association with accessing device

devices:delete:userSeenDevice

Delete user association with accessing device

dir:create:group

Create a group in the environment. Groups are used to organize a collection of user identities.

Create Group
Create Group Nesting

dir:read:group

Read a group in the environment. Groups are used to organize a collection of user identities.

Read All Groups
Read One Group
Read Group Nesting

dir:update:group

Update a group, including name, description, and user filter, which defines dynamic group membership. Adding users directly requires the Group Membership permission.

Update Group

dir:delete:group

Delete a group from the environment. Groups are used to organize a collection of user identities.

Delete Group
Delete Group Nesting

dir:create:groupMembership

Add a user to a group manually, rather than dynamically.

Add User to Group

dir:read:groupMembership

Read the group membership for a user.

Read All Users in a Group
Read All Users in Multiple Groups
Read All Users in a Group with Other User Attribute
Read All Group Names for User
Read All Group IDs for User
Read All Group Memberships for User
Read One Group Membership for User

dir:delete:groupMembership

Delete a user or subgroup from a group.

Remove User from Group

dir:read:groupSyncedRules

get group’s provisioning rule sync status

dir:create:passwordPolicy

Create a password policy for the environment. A password policy dictates the strength and complexity requirements for a password or passphrase.

Create Password Policy

dir:read:passwordPolicy

Read a list of password policies for the environment. A password policy dictates the strength and complexity requirements for a password or passphrase.

Read All Password Policies
Read One Password Policy

dir:update:passwordPolicy

Update a password policy for the environment. A password policy dictates the strength and complexity requirements for a password or passphrase.

Update Password Policy

dir:delete:passwordPolicy

Delete a password policy from the environment. A password policy dictates the strength and complexity requirements for a password or passphrase.

Delete Password Policy

dir:create:population

Create a population in the environment. A population defines a set of users, and a user can belong to one population only.

Create Population

dir:read:population

Read a list of populations in the environment. A population defines a set of users, and a user can belong to one population only.

Read All Populations
Read One Population
Read One Population Default IdP
Read User Population

dir:update:population

Update a population, including name and description, password policy, and population members. A population defines a set of users, and a user can belong to one population only.

Update Population
Update Population Default IdP
Update User Population

dir:delete:population

Delete a population from the environment. A population defines a set of users, and a user can belong to one population only.

Delete Population

dir:read:schema

Read the schema for the environment, including its attributes. A schema defines the user attributes in the environment.

Read All Schemas
Read All (Schema) Attributes
Read One Schema
Read One Attribute

dir:update:schema

Update a schema, including creating, updating, and deleting attributes. A schema defines the user attributes in the environment.

Create Attribute
Update Attribute (Put)
Update Attribute (Patch)

dir:delete:schema

Delete a schema from the environment. A schema defines the user attributes in the environment.

Delete Attribute

dir:create:user

Create a user in the environment.

Create User
Create User (Import)
Create User Import External Password

dir:import:user

Import users into the PingOne Directory. Imported users can include a password value.

dir:invite:user

Invite users

Send Admin Invite
Resend Admin Invite

dir:read:user

Read a list of users in the environment.

Read User or Users
Read User by ID
Read User Identity Provider
Read User Enabled

dir:update:user

Update a user account, including name, email address, and other attributes.

Update User
Update User Identity Provider
Update User
Update User Using JSON Array

dir:verify:user

Verify a user using a verification code. Send verification codes. Verify a user’s email address and send a verification email.

Verify User
Send/Resend User Verification Code
Send Email Verification (Code)
Verify Email (Code)

dir:delete:user

Delete a user from the environment.

Delete User

dir:lock:userAccount

Lock a user account. Locked accounts cannot sign on to PingOne.

User Account Lock

dir:unlock:userAccount

Unlock a user account. Locked accounts cannot sign on to PingOne.

User Account Unlock

dir:update:userEnabled

Enable or disable a user. Disabled users cannot sign on to PingOne.

Update User Enabled

dir:delete:userIdentityAssurance

Delete identity assurance claims data from a user. Identity assurance claims provide verified user data about the verification process used to provide access control for the user.

dir:update:userIdentityProvider

Define the authoritative identity provider for a user. An authoritative identity provider has authority over user records and credentials.

dir:create:userLinkedAccounts

Create a linked account for a user. A linked account is tied to a third-party identity provider for authentication.

Create Linked Account

dir:read:userLinkedAccounts

Read accounts linked to a user. A linked account is tied to a third-party identity provider for authentication.

Read Linked Accounts
Read One Linked Account

dir:delete:userLinkedAccounts

Delete a linked account for a user. A linked account is tied to a third-party identity provider for authentication.

Delete Linked Account

dir:update:userMfaBypass

Specify an MFA bypass period for a user. The user will not be prompted to carry out MFA until after this period expires.

dir:update:userMfaEnabled

Update the mfaEnabled status for a user. Specify whether MFA should be enabled for a user.

dir:read:userPassword

Read a user’s password state. The password state values can include OK, PASSWORD_LOCKED_OUT, and PASSWORD_EXPIRED.

Read Password State

dir:validate:userPassword

Validate a user’s password.

Password Check

dir:read:userSyncedStores

get user’s target store sync status

dir:update:userVerifyStatus

Update a user’s verification status.

earlyAccess:read:features

Read the early access features applicable to an environment.

Read Early Access Features

earlyAccess:update:features

Opt-in or opt-out of early access features available for an environment.

Update Early Access Features

enduseruiconfig:read:configs

View the Self Service and Application Portal pages.

experiences:create:experience

Create Design Center experiences. Design Center experiences define the sign-on requirements used to access applications.

Create Experience

experiences:read:experience

Read a list of the available Design Center experiences for an environment. Design Center experiences define the sign-on requirements used to access an application.

Read All Experiences
Read One Experience by ID
Read One Experience by Name

experiences:update:experience

Update Design Center experiences. Design Center experiences define the sign-on requirements used to access an application.

Update Experience

experiences:delete:experience

Delete Design Center experiences from the environment. Design Center experiences define the sign-on requirements used to access applications.

Delete Experience

externalServices:create:externalService

Create an external service

externalServices:invoke:externalService

Invoke an external service request

externalServices:read:externalService

Read a external service(s)

externalServices:update:externalService

Update an external service

externalServices:delete:externalService

Delete an external service

externalServices:read:secrets

Read external service secrets

externalServices:update:secrets

Update external service secrets

flowPolicies:read:flowPolicy

Read all DaVinci policies that are configured for use with PingOne applications.

Read All Flow Policies
Read One Flow Policy

formBuilder:create:form

Create a DaVinci form.

Create Custom Form
Import Form

formBuilder:read:form

Get a list of available DaVinci forms.

Export Form
Read One Form
Read Forms

formBuilder:update:form

Update an existing DaVinci form.

Update Form

formBuilder:delete:form

Delete a DaVinci form.

Delete One Form

formBuilder:read:recaptchaV2Config

Read the values for the Site Key and Secret Key fields of all Google reCAPTCHA verifications embedded in any DaVinci forms in a PingOne environment.

Read Recaptcha Configuration

formBuilder:update:recaptchaV2Config

Update the values for the Site Key and Secret Key fields of all Google reCAPTCHA verifications embedded in any DaVinci forms in a PingOne environment.

Update Recaptcha Configuration

formBuilder:delete:recaptchaV2Config

Delete the values for the Site Key and Secret Key fields of all Google reCAPTCHA verifications embedded in any DaVinci forms in a PingOne environment.

Delete Recaptcha Configuration

gateways:create:gateway

Create a gateway to connect your on-premise infrastructure to PingOne and authenticate user identities and data stored in an internal or external directory.

Create LDAP Gateway
Create PingFederate Connection
Create PingOne AIC Connection
Create PingAM Connection
Create RADIUS Gateway
Create API Gateway Integration
Create Authorize Gateway
Create Gateway Credentials

gateways:read:gateway

Read the configuration details of all PingOne gateways. Gateways connect your on-premise infrastructure to PingOne.

Read All Gateways
Read One Gateway
Read All Authorize Gateways
Read One Authorize Gateway
Read All Gateway Credentials
Read One Gateway Credential
Read All Gateway Instances
Read One Gateway Instance
Read All Authorize Gateway Instances

gateways:update:gateway

Update the settings for a PingOne gateway.

Update LDAP Gateway
Update RADIUS Gateway
Update Authorize Gateway

gateways:delete:gateway

Delete a gateway to remove the connection between your on-premise infrastructure and PingOne.

Delete Gateway
Delete Gateway Credentials

globalregistry:read:console

Access to PingOne administrator console.

identityProviders:create:identityProvider

Create an identity provider (IdP) resource. External IdP connections allow users to authenticate with PingOne using credentials provided by the IdP when configured as part of an authentication policy.

Create Identity Provider (Facebook)
Create Identity Provider (Google)
Create Identity Provider (LinkedIn Legacy Deprecated)
Create Identity Provider (LinkedIn OIDC)
Create Identity Provider (Yahoo)
Create Identity Provider (OpenID Connect)
Create Identity Provider (Amazon)
Create Identity Provider (X)
Create Identity Provider (Apple)
Create Identity Provider (Paypal)
Create Identity Provider (Microsoft)
Create Identity Provider (Github)
Create Identity Provider (SAML)
Discover OpenID Provider Metadata
Create Identity Provider Attribute (Facebook)
Create Identity Provider Attribute (Google)
Create Identity Provider Attribute (LinkedIn Legacy Deprecated)
Create Identity Provider Attribute (LinkedIn OIDC)
Create Identity Provider Attribute (Yahoo)
Create Identity Provider Attribute (OpenID Connect)
Create Identity Provider Attribute (Amazon)
Create Identity Provider Attribute (X)
Create Identity Provider Attribute (PayPal)
Create Identity Provider Attribute (Microsoft)
Create Identity Provider Attribute (Github)
Create Identity Provider Attribute (Apple)
Create Identity Provider Attribute (SAML)

identityProviders:read:identityProvider

Read identity provider (IdP) resources. External IdP connections allow users to authenticate to PingOne using credentials provided by the external IdP.

Read All Identity Providers
Read One Identity Provider
Read All Identity Provider Attributes
Read One Identity Provider Attribute

identityProviders:update:identityProvider

Update an identity provider (IdP) resource to change how users authenticate to PingOne using the credentials provided by the IdP.

Update Identity Provider
Update Identity Provider Attribute

identityProviders:delete:identityProvider

Delete an identity provider (IdP) resource. Users will no longer be able to use the external IdP connection to authenticate using credentials provided by the IdP.

Delete Identity Provider
Delete Identity Provider Attribute

identitycloud:create:orchestration

Create an Advanced Identity Cloud orchestration in a specific environment

identitycloud:update:orchestration

Update an Advanced Identity Cloud orchestration in a specific environment

identitycloud:admin:superadmin

Grants the Super Admin role in Advanced Identity Cloud which has full access to all administrative features and can manage every aspect of this tenant, including adding other administrators.

identitycloud:admin:tenantadmin

Grants the Tenant Admin role in Advanced Identity Cloud which has full access to all administrative features, except the ability to add other administrators.

idverifications:create:dataBasedIdentityVerification

Create data-based identity verification. Data-based identity verification runs matching and fraud analysis against user data and returns all personally identifiable information (PII) and a data match confidence score.

Submit Data-Based Identity Verification

idverifications:create:deviceOwnershipVerification

Create a device ownership request. A device ownership request initiates data-based identity verification using TransUnion TruValidate and checks the phone, email, and name associated with a user.

Submit Device Ownership Verification

idverifications:create:document

Submit a user-submitted document. User-submitted documents are government issued identity documents, such as a driver license or passport, used for identity verification.

Create Verification Document

idverifications:get:document

Read user-submitted documents. User-submitted documents are government issued identity documents, such as a driver license or passport, used for identity verification.

Read All Verification Documents
Read One Verification Document

idverifications:update:document

Update a user-submitted document. User-submitted documents are government issued identity documents, such as a driver license or passport, used for identity verification.

Update Verification Document
Complete Verification Documents
Process Verification Documents

idverifications:delete:document

Delete a user-submitted document. User-submitted documents are government issued identity documents, such as a driver license or passport, used for identity verification.

Delete Verification Document

idverifications:create:identityRecordMatching

Create Identity Record Matching. Identity Record Matching compares two sets of identity data and returns a score of confidence that the data match.

Submit Identity Record Match

idverifications:get:referenceData

Read data submitted by a user during a voice verification.

Read All Reference Data (deprecated)
Read One Reference Data (deprecated)

idverifications:delete:referenceData

Delete data submitted by a user during a voice verification.

Delete All Reference Data (deprecated)
Delete One Reference Data (deprecated)

idverifications:get:verifiedUserData

Read verified user data from a verification transaction.

Read All User Verified Data
Read One User Verified Data
Read All Verification Metadata
Read One Verification Metadata
Read All Verify Transaction Metrics
Read One Verify Transaction Metric

idverifications:update:verifiedUserData

Update verified user data from a verification transaction.

Update Verified Data Portrait Background

idverifications:delete:verifiedUserData

Delete verified user data from a verification transaction.

Delete All User Verified Data
Delete One User Verified Data
Delete All Verification Metadata
Delete One Verification Metadata
Delete All Verify Transaction Metrics
Delete One Verify Transaction Metric

idverifications:create:verifyPolicy

Create a PingOne Verify policy.

Create Verify Policy

idverifications:read:verifyPolicy

Read a PingOne Verify policy.

Read All Verify Policies
Read One Verify Policy

idverifications:update:verifyPolicy

Update a PingOne Verify policy.

Update Verify Policy

idverifications:delete:verifyPolicy

Delete a PingOne Verify policy.

Delete Verify Policy

idverifications:create:verifyTransactions

Create a user verification transaction.

Create Verify Transaction

idverifications:read:verifyTransactions

Read a user verification transaction.

Read All Verify Transactions
Read One Verify Transaction

idverifications:update:verifyTransactions

Update a user verification transaction.

Update Verify Transaction
Reset Verification (deprecated)

idverifications:delete:verifyTransactions

Delete a user verification transaction.

Delete Verify Transaction

idverifications:create:voicePhrase

Create the template that defines the phrase the user speaks during voice verification.

Create Custom Voice Phrase (deprecated)

idverifications:read:voicePhrase

Read the template that defines the phrase the user speaks during voice verification.

Read All Voice Phrases (deprecated)
Read One Voice Phrase (deprecated)

idverifications:update:voicePhrase

Update the template that defines the phrase the user speaks during voice verification.

Update Custom Voice Phrase (deprecated)

idverifications:delete:voicePhrase

Delete the template that defines the phrase the user speaks during voice verification.

Delete Custom Voice Phrase (deprecated)

idverifications:create:voicePhraseContent

Create the phrase that the user speaks aloud for voice verification.

Create Custom Voice Phrase Content (deprecated)

idverifications:read:voicePhraseContent

Read the phrase that the user speaks aloud for voice verification.

Read All Voice Phrase Contents (deprecated)
Read One Voice Phrase Content (deprecated)

idverifications:update:voicePhraseContent

Update the phrase that the user speaks aloud for voice verification.

Update Custom Voice Phrase Content (deprecated)

idverifications:delete:voicePhraseContent

Delete the phrase that the user speaks aloud for voice verification.

Delete Custom Voice Phrase Content (deprecated)

image:create:image

Upload an image to PingOne for an environment. The image can be used by other services within the environment, such as user profile.

Create Image

image:read:image

View any image that has been uploaded to PingOne for an environment.

Read Image

image:delete:image

Delete any image that has been uploaded to PingOne for an environment.

Delete Image

integrations:read:integration

Read a list of product integration kits, versions, and items in the application catalog.

Read All Integration Metadata
Read All Integration Versions Metadata
Read All Attributes of an Integration Version (SAML only)
Read One Integration Metadata
Read One Integration Version Metadata
Read One Attribute of an Integration Version (SAML only)
Download One Integration Version Asset

langmgt:create:language

Add a language to configure for an environment.

Create Language
Create Language
Create Language Localization Status
Update Language Localization Status
Create Translation

langmgt:read:language

Read a list of languages that are currently configured for an environment.

Read All Languages
Read One Language
Read Languages
Read One Language
Read Language Localization Status
Read One Language Localization Status
Read Translation

langmgt:update:language

Enable or disable a language for an environment or set a language as the default.

Update Language
Update Language
Update Translation

langmgt:delete:language

Delete a language from an environment.

Delete Language
Delete Language
Delete Language Localization Status
Delete Translation

ldapGateway:execute:directLdap

Allow specific clients, such as PingFederate and the PingOne DaVinci connector, to route LDAP operations through PingOne to your on-premise LDAP directories.

ldapGateway:validate:kerberos

Use Kerberos authentication through an LDAP gateway. Available only if you use Microsoft Active Directory as your LDAP directory.

ldapGateway:read:user

Read LDAP users using the LDAP gateway.

ldapGateway:validate:userPassword

Check a user’s password through a PingOne LDAP gateway. LDAP gateways connect PingOne with customer-managed LDAP directories.

licensing:update:environmentLicense

Update environment licenses

licensing:update:mutableProperties

Edit the attributes for a license, including the license name or environment assignment.

Update One License Name

mfa:create:createTestDevice

Create an MFA device for testing.

Create MFA User Device for testing

mfa:authenticate:device

Initiate device authentication.

Initiate Device Authentication
Initiate Device Authentication (PingID Desktop)
Initiate Device Authentication (Custom Notification)
Initiate Device Authentication (No User Name)
Initiate Device Authentication (One-time SMS)
Initiate Device Authentication (One-time Voice)
Initiate Device Authentication (One-time Email)
Select Device for Authentication
Validate OTP for Device
Check Assertion (PingID Desktop)
Check Assertion (FIDO Device)
Check Remember Me Device

mfa:read:device

Read MFA devices.

Read All MFA User Devices
Read One MFA User Device

mfa:create:deviceAuthenticationPolicy

Create an MFA policy. MFA policies are used to define and configure the authentication methods used in your authentication policy.

Create Device Authentication Policy
Create Device Authentication Policy (with Remember Me enabled)

mfa:read:deviceAuthenticationPolicy

Read an MFA policy. MFA policies are used to define and configure the authentication methods used in your authentication policy.

Read Device Authentication Policies
Read One Device Authentication Policy

mfa:update:deviceAuthenticationPolicy

Modify an existing MFA policyUpdate an MFA policy. MFA policies are used to define and configure the authentication methods used in your authentication policy.

Update Device Authentication Policy
Update Device Authentication Policy (env with PingID integration)
Migrate Device Authentication Policies

mfa:delete:deviceAuthenticationPolicy

Delete an MFA policy. MFA policies are used to define and configure the authentication methods used in your authentication policy.

Delete Device Authentication Policy

mfa:read:deviceRequirements

Read device requirements for a mobile application.

mfa:update:deviceRequirements

Update device requirements for a mobile application.

mfa:delete:deviceRequirements

Delete device requirements for a mobile application.

mfa:create:fidoDeviceMetadata

Create custom FIDO device metadata.

Add Custom FIDO Device - u2f
Add Custom FIDO Device - fido2

mfa:read:fidoDeviceMetadata

Read FIDO device metadata.

Read All FIDO Device Metadata
Read FIDO Device Metadata - single u2f device
Read FIDO Device Metadata - single fido2 device

mfa:delete:fidoDeviceMetadata

Delete custom FIDO device metadata.

Remove Custom FIDO Device

mfa:create:fidoPolicy

Create a FIDO policy. FIDO policies define which FIDO devices and authenticators can be used for registration and authentication.

Create FIDO Policy - all FIDO-certified authenticators
Create FIDO Policy - FIDO-certified and enterprise
Create FIDO Policy - specific authenticators

mfa:read:fidoPolicy

Read a FIDO policy. FIDO policies define which FIDO devices and authenticators can be used for registration and authentication.

Read All FIDO Policies
Read Single FIDO Policy

mfa:update:fidoPolicy

Update a FIDO policy. FIDO policies define which FIDO devices and authenticators can be used for registration and authentication.

Update FIDO Policy

mfa:delete:fidoPolicy

Delete a FIDO policy. FIDO policies define which FIDO devices and authenticators can be used for registration and authentication.

Delete Single FIDO Policy

mfa:read:mfaSettings

Read MFA settings.

Read MFA Settings

mfa:update:mfaSettings

Update MFA settings.

Update MFA Settings

mfa:delete:mfaSettings

Reset MFA settings.

Reset MFA Settings

mfa:read:oathJob

Retrieve an OATH Job

Check status of OATH token creation job
Check status of OATH token revoke job

mfa:create:oathToken

Add an OATH token to the environment. After you add the OATH token, you can specify it as an authentication method for a specific user. Relevant only for environments that include PingID.

Create OATH token (TOTP)
Create OATH token (HOTP)
Create multiple OATH tokens

mfa:read:oathToken

Read an OATH token that has been added to the environment. Relevant only for environments that include PingID.

Retrieve all OATH tokens
Retrieve OATH token by ID
Retrieve OATH token by serial number

mfa:update:oathToken

Resync an OATH token that has been added to the environment. Relevant only for environments that include PingID.

Resync OATH token
Resync OATH token paired with user

mfa:delete:oathToken

Delete an OATH token from the environment. Relevant only for environments that include PingID.

Revoke OATH token
Revoke multiple OATH tokens

mfa:read:offlineDevice

Retrieves the list of MFA devices configured for offline authentication.

mfa:create:pairingKey

Create a pairing key for an MFA device.

Create MFA Pairing Key

mfa:read:pairingKey

Read pairing keys for MFA devices.

Read One MFA Pairing Key

mfa:update:pairingKey

Update a user’s pairing key information

mfa:delete:pairingKey

Delete the pairing key for an MFA device.

Delete MFA Pairing Key

notifications:create:emailDomain

Create an email domain. Email domains are used for sending out email notifications to your users.

Create Trusted Email Domain
Create Trusted Email Address
Activate Trusted Email Address
Resend Verification Code To Email

notifications:read:emailDomain

Read the email domains. Email domains are used for sending out email notifications to your users.

Read All Trusted Email Domains
Read One Trusted Email Domain
Read Trusted Email Domain Ownership Status
Read Trusted Email Domain DKIM Status
Read Trusted Email Domain SPF Status
Read MAIL FROM Domain
Read All Trusted Email Addresses
Read One Trusted Email Address

notifications:update:emailDomain

Update an email domain. Email domains are used for sending out email notifications to your users.

Create MAIL FROM Domain

notifications:delete:emailDomain

Delete an email domain. Email domains are used for sending out email notifications to your users.

Delete Trusted Email Domain
Delete MAIL FROM Domain
Delete Trusted Email Address

notifications:create:notification

Send an event notification to a user.

Test Push Notifications

notifications:create:notificationsPolicy

Create a notification policy. Notification policies are used to limit the number of SMS/voice or email notifications that can be sent per day.

Create Notification Policy / Environment
Create Notification Policy / Environment (using custom providers)
Create Notification Policy / User
Create Notification Policy / user - claimed, unclaimed (instead of total)

notifications:read:notificationsPolicy

Read notification policies. Notification policies are used to limit the number of SMS/voice or email notifications that can be sent per day.

Read All Notification Policies
Read One Notification Policy

notifications:update:notificationsPolicy

Update a notification policy. Notification policies are used to limit the number of SMS/voice or email notifications that can be sent per day.

Update Notification Policy (with custom provider preference)
Update Notification Policy

notifications:delete:notificationsPolicy

Delete a notification policyDelete a notification policy. Notification policies are used to limit the number of SMS/voice or email notifications that can be sent per day.

Delete Notification Policy

notifications:read:notificationsSettings

Read fallback order for SMS/Voice providers and 'from' and 'reply to' fields for email notifications.

Read Notifications Settings
Read Notifications Settings (SMTP)
Read Custom Email Provider
Read One Phone Delivery Settings (include Verify templates)
Read All Phone Delivery Settings
Read One Phone Delivery Settings
Read WhatsApp Delivery Settings
Read WhatsApp Delivery Settings (including templates)

notifications:update:notificationsSettings

Update fallback order for SMS/Voice providers and reset 'from' and 'reply to' fields for email notifications.

Update Notifications Settings
Update Notifications Settings (SMTP)
Create Custom Email Provider
Create Phone Delivery Settings (custom)
Create Phone Delivery Settings (custom, OAUTH2 credentials)
Create Phone Delivery Settings (custom, custom header)
Update Phone Delivery Settings
Create Phone Delivery Settings (Twilio)
Create Phone Delivery Settings (Twilio Verify)
Create Phone Delivery Settings (Syniverse)
Create Phone Delivery Settings (Syniverse channels)
Update Phone Delivery Settings (Twilio)
Update Phone Delivery Settings (select Syniverse channels)
Create Phone Delivery Settings (custom, OAUTH2 JWT)
Create Phone Delivery Settings (Twilio Messaging Service)
Update Phone Delivery Settings (select Twilio Messaging Service)
Create WhatsApp Delivery Settings
Create WhatsApp Delivery Settings (specify number)

notifications:delete:notificationsSettings

Reset fallback order for SMS/Voice providers and reset 'from' and 'reply to' fields for email notifications.

Delete Notifications Settings
Delete Notifications Settings (SMTP)
Delete Phone Delivery Settings

notifications:read:quota

Read the daily notification quota set in notification policy.

notifications:read:template

Read a notification template. Notification templates are used to inform users about certain events in PingOne.

Read All Templates
Read One Template

notifications:create:templateContent

Create content for a notification template. Notification templates are used to inform users about some event types in PingOne.

Create Email Content
Create WhatsApp Content
Create SMS Content
Create SMS Content (including Twilio Verify template)
Create Voice Content
Create Push Content

notifications:read:templateContent

Read the content of a notification template. Notification templates are used to inform users about some event types in PingOne.

Read All Contents
Read One Content

notifications:update:templateContent

Update content for a notification template. Notification templates are used to inform users about some event types in PingOne.

Update WhatsApp Content
Update Email Content
Update SMS Content
Update Voice Content
Update Push Content
Patch Bulk Variant Contents

notifications:delete:templateContent

Delete the content of a notification template. Notification templates are used to inform users about some event types in PingOne.

Delete Content
Delete Bulk Variant Contents

notifications:reset:userQuota

Reset notifications quota

Reset Notification Quotas

orgmgt:create:deployment

Create deployments for other Ping products in the PingOne environment. These other products might require additional configuration outside of PingOne.

orgmgt:promote:environment

Promote an environment from sandbox to production. A sandbox environment is used to test functionality before deploying to production.

orgmgt:update:environment

Update environment properties to add or remove services, change the environment name or description, or update license information. Environments are the primary subdivision of an organization.

Update Bill of Materials
Update Environment Status
Update Environment
Update Environment Type

osmosis:check:connection

Test the provisioning connection to an external identity provider before saving the configuration.

Test Connection Configuration

osmosis:read:mapping

Read the attribute mapping for a provisioning rule. Attribute mapping defines how attributes from an external identity store correspond to attributes in PingOne.

Read One Mapping
Read One Rule Mapping

osmosis:update:mapping

Update the attribute mapping for a provisioning rule. Attribute mapping defines how attributes from an external identity store correspond to attributes in PingOne.

Import External Groups
Create Rule Mapping
Update Mapping

osmosis:delete:mapping

Delete an attribute mapping for a provisioning rule. Attribute mapping defines how attributes from an external identity store correspond to attributes in PingOne.

Delete Mapping

osmosis:read:plan

Read a provisioning plan. A provisioning plan is a list of all the provisioning rules in an environment.

Read All Plans
Read One Plan

osmosis:update:plan

Update a provisioning plan. A provisioning plan is a list of all the provisioning rules in an environment.

Create Plan
Update Plan

osmosis:delete:plan

Delete a provisioning plan. A provisioning plan is a list of all the provisioning rules in an environment.

Delete Plan

osmosis:create:revision

Create a provisioning configuration. A provisioning configuration includes the provisioning connection and provisioning rule.

Create Propagation Revision

osmosis:get:revision

Read a provisioning configuration. A provisioning configuration includes the provisioning connection and provisioning rule.

Read Latest Propagation Revision
Read Previous Propagation Revision

osmosis:read:rule

Read a provisioning rule. A provisioning rule defines which users are provisioned and how attributes are mapped between PingOne and the external identity store.

Read All Rules
Read One Rule
Read One Plan’s Rules
Read All Synced Rules for a User
Read One Synced Rule for a User
Read All Synced Rules for a Group
Read One Synced Rule for a Group
Read All Synced Groups for a Rule
Read One Synced Group for a Rule

osmosis:update:rule

Update a provisioning rule. A provisioning rule defines which users are provisioned and how attributes are mapped between PingOne and the external identity store.

Create Rule
Create Rule (Writeback)
Update Rule

osmosis:delete:rule

Delete a provisioning rule. A provisioning rule defines which users are provisioned and how attributes are mapped between PingOne and the external identity store.

Delete Rule

osmosis:read:store

Read a provisioning connection. A provisioning connection includes authorization information for the connection type and configuration options, such as provisioning and deprovisioning actions.

Read All Stores
Read One Store
Read All Synced Stores for a User (deprecated)
Read One Synced Store for a User (deprecated)
Identity Propagation Store Metadata (Aquera)
Identity Propagation Store Metadata (AzureActiveDirectorySAML2)
Identity Propagation Store Metadata (directory)
Identity Propagation Store Metadata (GitHubEMU)
Identity Propagation Store Metadata (GoogleApps)
Identity Propagation Store Metadata (LdapGateway)
Identity Propagation Store Metadata (PingOne)
Identity Propagation Store Metadata (Salesforce)
Identity Propagation Store Metadata (SalesforceContacts)
Identity Propagation Store Metadata (SCIM)
Identity Propagation Store Metadata (ServiceNow)
Identity Propagation Store Metadata (Slack)
Identity Propagation Store Metadata (Workday)
Identity Propagation Store Metadata (Zoom)

osmosis:update:store

Update a provisioning connection. A provisioning connection includes authorization information for the connection type and configuration options, such as provisioning and deprovisioning actions.

Create Store (Aquera)
Create Store (AzureActiveDirectorySAML2)
Create Store (directory)
Create Store (GitHubEMU)
Create Store (GoogleApps)
Create Store (LdapGateway)
Create Store (PingOne)
Create Store (Salesforce)
Create Store (SalesforceContacts)
Create Store (SCIM)
Create Store (ServiceNow)
Create Store (Slack)
Create Store (Workday)
Create Store (Zoom)
Update Store

osmosis:delete:store

Delete a provisioning connection. A provisioning connection includes authorization information for the connection type and configuration options, such as provisioning and deprovisioning actions.

Delete Store

permissions:read:applicationRoleAssignments

Read admin roles that are assigned to an application scope, including the role permissions. Roles are used by worker applications only.

permissions:read:gatewayRoleAssignments

Read the list of roles and the associated permissions associated with a gateway scope. The gateway scope defines the attributes that can be accessed in the external LDAP directory.

Read Gateway Role Assignments
Read One Gateway Role Assignment

permissions:read:groupRoleAssignments

Read the admin roles that are assigned to a group.

Read All Group Role Assignments
Read One Group Role Assignment

permissions:read:userRoleAssignments

Read admin roles that are assigned to a user, including the role permissions.

Read Role Assignments
Read One Role Assignment

pingenterprise:create:orchestration

Creates a Orchestration flow for Ping Enterprise deployment

pingenterprise:read:orchestration

Retrieve Orchestration flow for Ping Enterprise deployment

pingenterprise:update:orchestration

Updates Orchestration flow for Ping Enterprise deployment

pingenterprise:delete:orchestration

Deletes Orchestration flow for Ping Enterprise deployment

pingfederate:admin:auditor

Used only for SSO to PingFederate. Enables the PingFederate Auditor role for the PingOne admin in PingFederate.

pingfederate:admin:crypto

Used only for SSO to PingFederate. Enables the PingFederate Crypto Administrator role for the PingOne admin in PingFederate.

pingfederate:admin:expressions

Used only for SSO to PingFederate. Enables the PingFederate Expressions Administrator role for the PingOne admin in PingFederate.

pingfederate:admin:system

Used only for SSO to PingFederate. Enables the PingFederate Administrator role for the PingOne admin in PingFederate.

pingfederate:admin:users

Used only for SSO to PingFederate. Enables the PingFederate Users Administrator role for the PingOne admin in PingFederate.

pingid:read:activity

Read PingID user last activity

pingid:read:integration

Read PingID user integrations(services)

pingid:update:integration

Update PingID user integration(service)

pingid:execute:migration

Start an integration of PingID with PingOne.

pingid:read:migration

Check the status of the integration of PingID with PingOne.

pingid:validate:migration

Validate resources such as PingID authentication policies before integrating PingID with PingOne.

pingintelligence:create:orchestration

Creates a Orchestration flow for Ping Intelligence deployment

pingintelligence:read:orchestration

Retrieve Orchestration flow for Ping Intelligence deployment

pingintelligence:update:orchestration

Updates Orchestration flow for Ping Intelligence deployment

pingintelligence:delete:orchestration

Deletes Orchestration flow for Ping Intelligence deployment

prediction:create:prediction

Create a prediction

privilege:access:adminConsole

Access the PingOne Privilege console with administrative access.

privilege:read:adminConsole

Access the PingOne Privilege console with read-only administrative permissions.

privilege:create:onboardingToken

Generate onboarding links for the PinOne Privilege agent to onboard users to the environment for just in time access.

provisioning:get:connectionSensitiveConfiguration

Read the authentication details, which can include sensitive information, for a provisioning configuration. A provisioning configuration includes the provisioning connection and provisioning rule.

provisioning:create:provisioningSyncOrchestration

Create a provisioning sync orchestration for an environment. Sync orchestration is required by the PingOne gateway to provision users inbound into PingOne.

provisioning:update:provisioningSyncOrchestration

Update a provisioning sync orchestration to allow a gateway to provision users to a PingOne environment. Sync orchestration is required by the PingOne gateway to provision users inbound into PingOne.

radiusGateway:read:session

Read radius session details for audit purposes

ratelimiting:create:rateLimitConfigs

Configure API rate limits for specific IP addresses. Rate limits determine the number of API requests allowed during a specific time period.

Create Rate Limit Configuration

ratelimiting:read:rateLimitConfigs

Read the API rate limit configuration for specific IP addresses. Rate limits determine the number of API requests allowed during a specific time period.

Read All Rate Limit Configurations
Read One Rate Limit Configuration

ratelimiting:update:rateLimitConfigs

Update the API rate limit configuration for specific IP addresses. Rate limits determine the number of API requests allowed during a specific time period.

ratelimiting:delete:rateLimitConfigs

Remove specific IP addresses from an API rate limit configuration. Rate limits determine the number of API requests allowed during a specific time period.

Delete Rate Limit Configuration

ratelimiting:read:rateLimits

Read the API rate limits allowed for each rate limit group under a particular license. Rate limits determine the number of API requests allowed during a specific time period.

resources:create:attribute

Create an attribute for a custom resource. Custom resource attributes are mapped as claims in access tokens to convey additional information about their use to applications.

Create Resource Attribute

resources:read:attribute

Read a list of custom attributes for a resource. Custom resource attributes are mapped as claims in access tokens to convey additional information about their use to applications.

Read All Resource Attributes
Read One Resource Attribute

resources:update:attribute

Update an attribute for a custom resource. Custom resource attributes are mapped as claims in access tokens to convey additional information about their use to applications.

Update Resource Attribute

resources:delete:attribute

Delete a custom attribute from a resource. Custom resource attributes are mapped as claims in access tokens to convey additional information about their use to applications.

Delete Resource Attribute

resources:create:resource

Create a resource. Resources are protected endpoints that applications can access using OAuth 2 authorization services.

Create Resource
Create Application Resource

resources:read:resource

Read the resources in the environment. Resources are protected endpoints that applications can access using OAuth 2 authorization services.

Read All Resources
Read One Resource
Read All Application Resources
Read One Application Resource

resources:update:resource

Update the configuration of a resource. Resources are the protected endpoints that applications can access using OAuth 2 authorization services.

Update Resource
Update Application Resource

resources:delete:resource

Delete a resource. Resources are protected endpoints that applications can access using OAuth 2 authorization services.

Delete Resource
Delete Application Resource

resources:create:scope

Create a scope for a resource. Resource scopes can be associated with applications and define application access to user details, such as name and email address.

Create Custom resource scope
Create PingOne access control scope
Create OpenID Connect resource scope

resources:read:scope

Read the scope for a resource. Resource scopes can be associated with applications and define application access to user details, such as name and email address.

Read All Scopes (Resource)
Read One Scope
Read Application Permissions

resources:update:scope

Update the scope for a resource. Resource scopes can be associated with applications and define application access to user details, such as name and email address.

Update Scope
Update PingOne access control scope

resources:delete:scope

Delete a scope from a resource. Resource scopes can be associated with applications and define application access to user details, such as name and email address.

Delete Scope

risk:create:evaluation

Create a risk evaluation, which is used to calculate the risk level and other risk-related details associated with an event.

Create Risk Evaluation
Create Risk Evaluation (with custom input)
Create Risk Evaluation (using targeted risk policies)
Create Risk Evaluation (includes device trust predictor)

risk:read:evaluation

Read risk evaluation details. Risk evaluations are used to calculate the risk level and other risk-related details associated with an event.

Read One Risk Evaluation

risk:update:evaluation

Update a risk evaluation with the completion status to allow the learning mechanism to improve risk evaluation precision.

Update Risk Evaluation

risk:create:feedback

Create risk feedback

Send Risk Evaluation Feedback

risk:create:policy

Create a risk policy for use in risk evaluations.

Create Risk Policy Set
Create Risk Policy Set - Targeted Policy no Scores (PingID users)
Create Risk Policy Set - Targeted Policy with Mitigations

risk:read:policy

Read risk policies, which are used in risk evaluations.

Read One Risk Policy Set
Read Risk Policy Sets
Read Risk Policy Sets (with targeted policy order)

risk:update:policy

Modify an existing risk policy. Risk policies are used in risk evaluations.

Reorder Targeted Risk Policies
Update Risk Policy Set

risk:delete:policy

Delete a risk policy. Risk policies are used in risk evaluations.

Delete Risk Policy Set

risk:create:predictor

Create a risk predictor for use in risk policies.

Create Risk Predictor (Composite with country)
Create Risk Predictor (Composite with country and user group)
Create Risk Predictor (Custom - IP range)
Create Risk Predictor (Custom - numeric range)
Create Risk Predictor (Custom - string matching)
Create Risk Predictor (Suspicious device)
Create Risk Predictor (Traffic anomaly)

risk:read:predictor

Read risk predictors, which are used in risk policies.

Read All Risk Predictors
Read One Risk Predictor

risk:update:predictor

Modify an existing risk predictor for use in risk policies.

Update Custom Risk Predictor
Update AITM Predictor
Update Bot Detection Predictor (rule exclusion)

risk:delete:predictor

Delete a risk predictor. Risk predictors are used in risk policies.

Delete Risk Predictor

risk:read:riskSettings

Read general Protect settings, such as data retention periods.

Read Protect Settings

risk:update:riskSettings

Update general Protect settings, such as data retention periods.

Update Protect Settings

risk:reset:userProfile

Erase all risk data for specific user, for example, user location history

Erase Risk Data for User

riskDetection:create:evaluation

Create detection evaluations for risk service

scim:read:schema

Read the schema for the environment, including its attributes, using the SCIM API. A schema defines the user attributes in the environment.

Read SCIM2 Resource Types
Read SCIM2 Schemas
Read Service Provider Configuration

scim:create:user

Create a user in the environment using the SCIM API.

Create SCIM User
Create Direct-mapped User

scim:read:user

Read a list of users in the environment using the SCIM API.

Read All SCIM Users (search)
Read All SCIM Users
Read One SCIM User
Read All Direct-mapped Users (search)
Read All Direct-mapped Users
Read One Direct-mapped User

scim:update:user

Update a user account, including name, email address, and other attributes, using the SCIM API.

Update SCIM User
Patch SCIM User
Update Direct-mapped User
Patch Direct-mapped User

scim:delete:user

Delete a user from the environment using the SCIM API.

Delete SCIM User
Delete Direct-mapped User

solutions:create:config

Create new or reset an existing configuration for the customer or workforce Getting Started experience to assign default flows for registration, authentication, profile management, and account recovery.

solutions:read:config

Read the configuration data for the CIAM or workforce Getting Started experiences, such as the flows used for registration, authentication, profile management, and account recovery.

solutions:update:config

Update the configuration of the customer or workforce Getting Started experience to use different flows for registration, authentication, profile management, or account recovery.

solutions:read:flow

Read the list of flows available as part of the getting started experience in the admin console.

solutions:read:token

Retrieve a DaVinci access token.

subscriptions:create:subscription

Create a webhook to send event information to an external monitoring system.

Create Subscriptions
Test Subscription

subscriptions:read:subscription

Read webhook information. Webhooks are used to subscribe to events of interest in PingOne and push the event information to an external monitoring system.

Read All Subscriptions
Read One Subscription

subscriptions:test:subscription

Test the webhook connection to your SIEM system to ensure that it is working properly. Webhooks allow you to use external tools to monitor PingOne events.

subscriptions:update:subscription

Update the properties or filters for a webhook to change the information that is sent to your external monitoring system.

Update Subscription

subscriptions:delete:subscription

Delete a webhook to stop sending event information to your external monitoring system.

Delete Subscription

traffic:create:inboundTrafficPolicy

Create inbound traffic policies for the environment. Inbound traffic policies are used to allow or block traffic coming through Cloudflare custom domains based on rules defined in the policy.

Create Inbound Traffic Policy

traffic:read:inboundTrafficPolicy

Read inbound traffic policies for the environment. Inbound traffic policies are used to allow or block traffic coming through Cloudflare custom domains based on rules defined in the policy.

Read Inbound Traffic Policies
Read One Inbound Traffic Policy

traffic:update:inboundTrafficPolicy

Update inbound traffic policies for the environment. Inbound traffic policies are used to allow or block traffic coming through Cloudflare custom domains based on rules defined in the policy.

Update Inbound Traffic Policy

traffic:delete:inboundTrafficPolicy

Delete inbound traffic policies for the environment. Inbound traffic policies are used to allow or block traffic coming through Cloudflare custom domains based on rules defined in the policy.

Delete Inbound Traffic Policy

traffic:read:ingressSettings

Read ingress settings for the environment. Ingress settings determine whether traffic requests that aren’t sent through a custom domain are blocked or allowed.

traffic:update:ingressSettings

Update ingress settings for the environment. Ingress settings determine whether traffic requests that aren’t sent through a custom domain are blocked or allowed.

visualization:read:apiUsage

View the API Usage dashboard. The API Usage dashboard shows an overview of how your peak API usage trends against the limits allowed by your license per rate limit group.

visualization:read:authentication

View the Authentication dashboard. The Authentication dashboard shows a summary of sign-on activity through PingOne and additional authentication metrics for the environment.

visualization:read:dashboard

See dashboards

visualization:read:davinciMetrics

Read PingOne DaVinci metrics using the metrics API. These metrics are also used by the DaVinci Dashboard and provide information about flow and connector executions.

Read DaVinci Flow Execution Counts
Read DaVinci Connector Execution Counts
Read DaVinci Flow Node Metrics

visualization:create:exploration

Create a data exploration object for use with dashboards and report generation.

visualization:read:exploration

Read the data for a data exploration object. Data exploration objects are used with dashboards and report generation.

visualization:read:provisioning

View the Provisioning dashboard. The Provisioning dashboard shows monitoring related to identity synchronization between PingOne directory and your target or source identity stores.

visualization:read:template

Read data exploration template

visualization:read:userDemographics

Read the User Demographics dashboard and user demographic data. User demographic data provides information on the distribution of users by population and operating system and browser usage by service.