---
title: SAML Sign-On Flow
description: Workflow showing how to configure a SAML application, group, and sign-on policy and complete a basic PingOne SAML sign-on flow
component: pingone-api
page_id: pingone-api:workflow-library:platform-sso-and-authorization/saml/saml-sign-on-flow/index
canonical_url: https://developer.pingidentity.com/pingone-api/workflow-library/platform-sso-and-authorization/saml/saml-sign-on-flow/index.html
llms_txt: https://developer.pingidentity.com/pingone-api/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-08-11
---

# SAML Sign-On Flow

This activity shows you how to create a basic PingOne sign-on flow for a SAML application.

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | This solution uses group access control properties set on the application. The request descriptions for creating the SAML application and the user group provide more details on how to configure access control in this workflow. For general information about access control, refer to [Control access to applications through roles and groups](../../../../foundations/pingone-roles-scopes-and-permissions/control-access-to-applications-through-roles-and-groups.html). |

The following operations are supported by the PingOne APIs:

* Create a group

* Create a SAML application

* Create a sign-on policy

* Create a login sign-on policy action

* Create a user

* Initiate a SAML authorize request

* Use flow APIs to complete the login

Click the **Run in Postman** button below to fork, or download and import, the Postman collection for this workflow to your workspace.

[Run in Postman](https://god.gw.postman.com/run-collection/18568624-cf6d652a-2338-4e26-ac96-574b3a907d40?action=collection%2Ffork\&source=rip_markdown\&collection-url=entityId%3D18568624-cf6d652a-2338-4e26-ac96-574b3a907d40%26entityType%3Dcollection%26workspaceId%3D3550b170-7818-4801-b1eb-dcb7b3f64263#?env%5BPingOne%20Workflow%20Library%20Template%20%28release%3A%202025-04-17%29%5D=W3sia2V5IjoidGxkIiwidmFsdWUiOiJjb20iLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYXV0aFBhdGgiLCJ2YWx1ZSI6Imh0dHBzOi8vYXV0aC5waW5nb25lLnt7dGxkfX0iLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYXBpUGF0aCIsInZhbHVlIjoiaHR0cHM6Ly9hcGkucGluZ29uZS57e3RsZH19L3YxIiwiZW5hYmxlZCI6dHJ1ZSwidHlwZSI6ImRlZmF1bHQifSx7ImtleSI6ImFkbWluRW52SUQiLCJ2YWx1ZSI6IiIsImVuYWJsZWQiOnRydWUsInR5cGUiOiJkZWZhdWx0In0seyJrZXkiOiJhZG1pbkFwcElEIiwidmFsdWUiOiIiLCJlbmFibGVkIjp0cnVlLCJ0eXBlIjoiZGVmYXVsdCJ9LHsia2V5IjoiYWRtaW5BcHBTZWNyZXQiLCJ2YWx1ZSI6IiIsImVuYWJsZWQiOnRydWUsInR5cGUiOiJkZWZhdWx0In0seyJrZXkiOiJlbnZJRCIsInZhbHVlIjoiIiwiZW5hYmxlZCI6dHJ1ZSwidHlwZSI6ImRlZmF1bHQifV0=)
