> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# PingOne Webhook Setup Guide

> Configure PingOne to deliver events to StackOne.

## Prerequisites

The connector should already be set up, with a Connector Profile and a Linked Account. See [Getting Started](/connectors/pingone#getting-started) on the PingOne connector page.

<section data-guide-section data-guide-scopes="">
  <h2>Automatic webhook subscription</h2>

  <p>StackOne creates and manages the PingOne webhook subscription automatically when the account is connected, and deletes it when the account is disconnected. There is nothing to configure in PingOne.</p>

  <Steps>
    <Step title="Admin role requirements">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>The PingOne user who signs in during the StackOne connection must be allowed to manage subscriptions in the environment.</p>

        <ul>
          <li>Assign <strong>Environment Admin</strong> at the environment scope, or <strong>Organization Admin</strong> at the organization scope. <strong>Identity Data Admin</strong> alone cannot create subscriptions.</li>
        </ul>
      </div>
    </Step>

    <Step title="Select events in StackOne">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Enable the webhook events you want on the PingOne connector in StackOne. StackOne registers one environment-wide subscription, named <strong>StackOne</strong>, for exactly those events and re-creates it when the selection changes. It appears in the PingOne Admin Console under <strong>Integrations</strong> > <strong>Webhooks</strong>.</p>
      </div>
    </Step>
  </Steps>
</section>

<section data-guide-section data-guide-scopes="">
  <h2>Available webhook events</h2>

  <p>The following PingOne audit events can be enabled. Only events selected in StackOne are included in the subscription, and PingOne does not deliver events that are not subscribed.</p>

  <Steps>
    <Step title="Users events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne users.</p>

        <ul>
          <li><strong>User Created</strong> (`USER.CREATED`) — Fired when a user is created in the environment</li>
          <li><strong>User Updated</strong> (`USER.UPDATED`) — Fired when a user's attributes are updated</li>
          <li><strong>User Deleted</strong> (`USER.DELETED`) — Fired when a user is deleted</li>
          <li><strong>User Locked</strong> (`USER.LOCKED`) — Fired when a user account is locked</li>
          <li><strong>User Unlocked</strong> (`USER.UNLOCKED`) — Fired when a locked user account is unlocked</li>
        </ul>
      </div>
    </Step>

    <Step title="Passwords events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne passwords.</p>

        <ul>
          <li><strong>Password Set</strong> (`PASSWORD.SET`) — Fired when a user's password is set by an administrator or API call</li>
          <li><strong>Password Reset</strong> (`PASSWORD.RESET`) — Fired when a user resets their password</li>
        </ul>
      </div>
    </Step>

    <Step title="Groups events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne groups.</p>

        <ul>
          <li><strong>Group Created</strong> (`GROUP.CREATED`) — Fired when a group is created</li>
          <li><strong>Group Updated</strong> (`GROUP.UPDATED`) — Fired when a group is updated</li>
          <li><strong>Group Deleted</strong> (`GROUP.DELETED`) — Fired when a group is deleted</li>
          <li><strong>Member of Group Created</strong> (`MEMBER_OF_GROUP.CREATED`) — Fired when a user or group is added as a member of a group</li>
          <li><strong>Member of Group Deleted</strong> (`MEMBER_OF_GROUP.DELETED`) — Fired when a user or group is removed from a group</li>
        </ul>
      </div>
    </Step>

    <Step title="Populations events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne populations.</p>

        <ul>
          <li><strong>Population Created</strong> (`POPULATION.CREATED`) — Fired when a population is created</li>
          <li><strong>Population Updated</strong> (`POPULATION.UPDATED`) — Fired when a population is updated</li>
          <li><strong>Population Deleted</strong> (`POPULATION.DELETED`) — Fired when a population is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="Applications events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne applications.</p>

        <ul>
          <li><strong>Application Created</strong> (`APPLICATION.CREATED`) — Fired when an application is created</li>
          <li><strong>Application Updated</strong> (`APPLICATION.UPDATED`) — Fired when an application's configuration is updated</li>
          <li><strong>Application Deleted</strong> (`APPLICATION.DELETED`) — Fired when an application is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="Roles events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne roles.</p>

        <ul>
          <li><strong>Role Created</strong> (`ROLE.CREATED`) — Fired when a custom admin role is created</li>
          <li><strong>Role Updated</strong> (`ROLE.UPDATED`) — Fired when a custom admin role is updated</li>
          <li><strong>Role Deleted</strong> (`ROLE.DELETED`) — Fired when a custom admin role is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="Role Assignments events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne role assignments.</p>

        <ul>
          <li><strong>Role Assignment Created</strong> (`ROLE_ASSIGNMENT.CREATED`) — Fired when an admin role is assigned to a user, group or application</li>
          <li><strong>Role Assignment Deleted</strong> (`ROLE_ASSIGNMENT.DELETED`) — Fired when an admin role assignment is removed</li>
        </ul>
      </div>
    </Step>

    <Step title="Policies events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne password policies and sign-on policies.</p>

        <ul>
          <li><strong>Policy Created</strong> (`POLICY.CREATED`) — Fired when a password policy or sign-on policy is created</li>
          <li><strong>Policy Updated</strong> (`POLICY.UPDATED`) — Fired when a password policy or sign-on policy is updated</li>
          <li><strong>Policy Deleted</strong> (`POLICY.DELETED`) — Fired when a password policy or sign-on policy is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="Identity Providers events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne identity providers.</p>

        <ul>
          <li><strong>Identity Provider Created</strong> (`IDENTITY_PROVIDER.CREATED`) — Fired when an external identity provider is created</li>
          <li><strong>Identity Provider Updated</strong> (`IDENTITY_PROVIDER.UPDATED`) — Fired when an external identity provider is updated</li>
          <li><strong>Identity Provider Deleted</strong> (`IDENTITY_PROVIDER.DELETED`) — Fired when an external identity provider is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="Sign-On Policies events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne sign-on policies.</p>

        <ul>
          <li><strong>Sign On Policy Assignment Created</strong> (`SIGN_ON_POLICY_ASSIGNMENT.CREATED`) — Fired when a sign-on policy is assigned to an application</li>
          <li><strong>Sign On Policy Assignment Deleted</strong> (`SIGN_ON_POLICY_ASSIGNMENT.DELETED`) — Fired when a sign-on policy assignment is removed from an application</li>
        </ul>
      </div>
    </Step>

    <Step title="MFA events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne mfa.</p>

        <ul>
          <li><strong>Device Authentication Policy Created</strong> (`DEVICE_AUTHENTICATION_POLICY.CREATED`) — Fired when an MFA device authentication policy is created</li>
          <li><strong>Device Authentication Policy Updated</strong> (`DEVICE_AUTHENTICATION_POLICY.UPDATED`) — Fired when an MFA device authentication policy is updated</li>
          <li><strong>Device Authentication Policy Deleted</strong> (`DEVICE_AUTHENTICATION_POLICY.DELETED`) — Fired when an MFA device authentication policy is deleted</li>
        </ul>
      </div>
    </Step>

    <Step title="MFA Devices events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne mfa devices.</p>

        <ul>
          <li><strong>MFA Device Created</strong> (`DEVICE.CREATED`) — Fired when an MFA device is added to a user</li>
          <li><strong>MFA Device Updated</strong> (`DEVICE.UPDATED`) — Fired when a user's MFA device is updated</li>
          <li><strong>MFA Device Nickname Updated</strong> (`DEVICE.NICKNAME_UPDATED`) — Fired when a user's MFA device nickname is changed</li>
          <li><strong>MFA Device Deleted</strong> (`DEVICE.DELETED`) — Fired when an MFA device is removed from a user</li>
        </ul>
      </div>
    </Step>

    <Step title="Certificates events">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>Events on PingOne certificates.</p>

        <ul>
          <li><strong>Certificate Created</strong> (`CERTIFICATE.CREATED`) — Fired when a certificate is created or imported</li>
          <li><strong>Certificate Updated</strong> (`CERTIFICATE.UPDATED`) — Fired when a certificate is updated</li>
          <li><strong>Certificate Deleted</strong> (`CERTIFICATE.DELETED`) — Fired when a certificate is deleted</li>
        </ul>
      </div>
    </Step>
  </Steps>
</section>

<section data-guide-section data-guide-scopes="">
  <h2>Delivery format</h2>

  <p>Details of how PingOne delivers events to StackOne.</p>

  <Steps>
    <Step title="JSON payloads">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>StackOne creates the subscription in the Ping Activity format. PingOne sends a JSON array of up to 50 events per HTTP POST, and StackOne processes each event in the array separately. The event type is in `action.type`, the affected record in `resources`, the user or client that made the change in `actors`, and the time PingOne recorded the event in `recordedAt`. StackOne uses the affected record's ID (`resources[0].id`) as the event ID.</p>
      </div>
    </Step>

    <Step title="Signature verification">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>PingOne does not sign webhook deliveries. Deliveries are sent over HTTPS with TLS certificate verification enabled.</p>
      </div>
    </Step>

    <Step title="Retries">
      <div data-guide-step data-guide-scopes="" data-guide-display-scopes-list="">
        <p>PingOne flushes queued events about once a minute and retries a delivery until it receives a 200 response, holding later events behind it. If the endpoint is unreachable for more than 7 days, PingOne starts to drop events.</p>
      </div>
    </Step>
  </Steps>
</section>

## Verify

Your Connector should now be able to receive and process events. Try triggering an event and you should see an Event appear in the Connector logs.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.