Prerequisites
The connector should already be set up, with a Connector Profile and a Linked Account. See Getting Started on the PingOne connector page.Automatic webhook subscription
StackOne creates and manages the PingOne webhook subscription automatically when the account is connected, and deletes it when the account is disconnected. There is nothing to configure in PingOne.
Admin role requirements
The PingOne user who signs in during the StackOne connection must be allowed to manage subscriptions in the environment.
- Assign Environment Admin at the environment scope, or Organization Admin at the organization scope. Identity Data Admin alone cannot create subscriptions.
Select events in StackOne
Enable the webhook events you want on the PingOne connector in StackOne. StackOne registers one environment-wide subscription, named StackOne, for exactly those events and re-creates it when the selection changes. It appears in the PingOne Admin Console under Integrations > Webhooks.
Available webhook events
The following PingOne audit events can be enabled. Only events selected in StackOne are included in the subscription, and PingOne does not deliver events that are not subscribed.
Users events
Events on PingOne users.
- User Created (
USER.CREATED) — Fired when a user is created in the environment - User Updated (
USER.UPDATED) — Fired when a user’s attributes are updated - User Deleted (
USER.DELETED) — Fired when a user is deleted - User Locked (
USER.LOCKED) — Fired when a user account is locked - User Unlocked (
USER.UNLOCKED) — Fired when a locked user account is unlocked
Passwords events
Events on PingOne passwords.
- Password Set (
PASSWORD.SET) — Fired when a user’s password is set by an administrator or API call - Password Reset (
PASSWORD.RESET) — Fired when a user resets their password
Groups events
Events on PingOne groups.
- Group Created (
GROUP.CREATED) — Fired when a group is created - Group Updated (
GROUP.UPDATED) — Fired when a group is updated - Group Deleted (
GROUP.DELETED) — Fired when a group is deleted - Member of Group Created (
MEMBER_OF_GROUP.CREATED) — Fired when a user or group is added as a member of a group - Member of Group Deleted (
MEMBER_OF_GROUP.DELETED) — Fired when a user or group is removed from a group
Populations events
Events on PingOne populations.
- Population Created (
POPULATION.CREATED) — Fired when a population is created - Population Updated (
POPULATION.UPDATED) — Fired when a population is updated - Population Deleted (
POPULATION.DELETED) — Fired when a population is deleted
Applications events
Events on PingOne applications.
- Application Created (
APPLICATION.CREATED) — Fired when an application is created - Application Updated (
APPLICATION.UPDATED) — Fired when an application’s configuration is updated - Application Deleted (
APPLICATION.DELETED) — Fired when an application is deleted
Roles events
Events on PingOne roles.
- Role Created (
ROLE.CREATED) — Fired when a custom admin role is created - Role Updated (
ROLE.UPDATED) — Fired when a custom admin role is updated - Role Deleted (
ROLE.DELETED) — Fired when a custom admin role is deleted
Role Assignments events
Events on PingOne role assignments.
- Role Assignment Created (
ROLE_ASSIGNMENT.CREATED) — Fired when an admin role is assigned to a user, group or application - Role Assignment Deleted (
ROLE_ASSIGNMENT.DELETED) — Fired when an admin role assignment is removed
Policies events
Events on PingOne password policies and sign-on policies.
- Policy Created (
POLICY.CREATED) — Fired when a password policy or sign-on policy is created - Policy Updated (
POLICY.UPDATED) — Fired when a password policy or sign-on policy is updated - Policy Deleted (
POLICY.DELETED) — Fired when a password policy or sign-on policy is deleted
Identity Providers events
Events on PingOne identity providers.
- Identity Provider Created (
IDENTITY_PROVIDER.CREATED) — Fired when an external identity provider is created - Identity Provider Updated (
IDENTITY_PROVIDER.UPDATED) — Fired when an external identity provider is updated - Identity Provider Deleted (
IDENTITY_PROVIDER.DELETED) — Fired when an external identity provider is deleted
Sign-On Policies events
Events on PingOne sign-on policies.
- Sign On Policy Assignment Created (
SIGN_ON_POLICY_ASSIGNMENT.CREATED) — Fired when a sign-on policy is assigned to an application - Sign On Policy Assignment Deleted (
SIGN_ON_POLICY_ASSIGNMENT.DELETED) — Fired when a sign-on policy assignment is removed from an application
MFA events
Events on PingOne mfa.
- Device Authentication Policy Created (
DEVICE_AUTHENTICATION_POLICY.CREATED) — Fired when an MFA device authentication policy is created - Device Authentication Policy Updated (
DEVICE_AUTHENTICATION_POLICY.UPDATED) — Fired when an MFA device authentication policy is updated - Device Authentication Policy Deleted (
DEVICE_AUTHENTICATION_POLICY.DELETED) — Fired when an MFA device authentication policy is deleted
MFA Devices events
Events on PingOne mfa devices.
- MFA Device Created (
DEVICE.CREATED) — Fired when an MFA device is added to a user - MFA Device Updated (
DEVICE.UPDATED) — Fired when a user’s MFA device is updated - MFA Device Nickname Updated (
DEVICE.NICKNAME_UPDATED) — Fired when a user’s MFA device nickname is changed - MFA Device Deleted (
DEVICE.DELETED) — Fired when an MFA device is removed from a user
Certificates events
Events on PingOne certificates.
- Certificate Created (
CERTIFICATE.CREATED) — Fired when a certificate is created or imported - Certificate Updated (
CERTIFICATE.UPDATED) — Fired when a certificate is updated - Certificate Deleted (
CERTIFICATE.DELETED) — Fired when a certificate is deleted
Delivery format
Details of how PingOne delivers events to StackOne.
JSON payloads
StackOne creates the subscription in the Ping Activity format. PingOne sends a JSON array of up to 50 events per HTTP POST, and StackOne processes each event in the array separately. The event type is in action.type, the affected record in resources, the user or client that made the change in actors, and the time PingOne recorded the event in recordedAt. StackOne uses the affected record’s ID (resources[0].id) as the event ID.
Signature verification
PingOne does not sign webhook deliveries. Deliveries are sent over HTTPS with TLS certificate verification enabled.
Retries
PingOne flushes queued events about once a minute and retries a delivery until it receives a 200 response, holding later events behind it. If the endpoint is unreachable for more than 7 days, PingOne starts to drop events.