Configure PingFederate for agent IAM
Enterprise
Appropriate Vault Enterprise license or HCP Vault Dedicated cluster required.
Configure users and OIDC applications in PingFederate to use with Vault Enterprise agentic IAM.
Before you start
- You must have a PingFederate client.
- You must have
curlor some other tool to make API calls. - You must have
jqinstalled to use the example commands as written. - You must have installed the
VaultPathAccessProcessorplugin to PingFederate.
Step 1: Create the RAR processor instance
Create a PingFederate authorization detail processor instance for the VaultPathAccessProcessor plugin.
Open the PingFederate admin console.
Choose Applications.
Select OAuth.
Select Authorization Detail Processors.
Select Create New Instance.
Configure the new processor instance's Instance Name set to
Vault Path Access Processor.Set the Instance ID to
vault-path-access-processorSet the Type to
Vault Path Access ProcessorSet the Parent Instance to
None.Select Next.
On the Summary tab, verify these settings.
- Instance Name:
Vault Path Access Processor - Instance ID:
vaultpathaccessprocessor - Type:
Vault Path Access Processor - Class Name:
com.hashicorp.vault.ping.VaultPathAccessProcessor - Supported Authorization Detail Types:
vault:path_access - Parent Instance Name:
None
- Instance Name:
Step 2: Add the VaultPathAccessProcessor authorization detail type
Globally register the RAR authorization detail type from Vault in PingFederate, and associate it with the processor instance.
Open the PingFederate admin console.
Navigate to the System screen.
Select OAuth Settings.
Choose Authorization Detail Types.
Choose Add Authorization detail type configuration.
Configure the detail type with Type of
vault:path_access.Set Description to
Vault path and capability authorization details.Select Authorization Detail Processor to
Vault Path Access Processor.Choose Save.
Step 3: Create the default JWT Access Token Manager for RAR
Create the default JWT Access Token Manager used for RAR-capable tokens.
PingFederate issues OAuth access tokens as signed JWTs. Vault, as an OAuth resource server, validates these JWTs and maps their claims to a Vault identity.
Open the PingFederate admin console.
Navigate through the UI to Applications.
Click OAuth.
Select Access Token Management.
Select Create New Instance.
Set the instance to have Instance Name of
Default.Set Instance ID to
default.Set Type to
JSON Web Tokens.Set Parent Instance to
None.Confirm the remaining fields match these values:
- Token Lifetime:
120 - Use Centralized Signing Key: ✅ checked
- JWS Algorithm:
RSA using SHA-256 - Active Symmetric Key ID:
-- Select One -- (leave) - Active Signing Certificate Key ID:
-- Select One -- (leave) - JWE Algorithm:
-- Select One -- (leave) - JWE Content Encryption Algorithm:
-- Select One -- (leave) - Active Symmetric Encryption Key ID:
-- Select One -- (leave) - Asymmetric Encryption Key: (blank)
- Asymmetric Encryption JWKS URL: (blank)
- Enable Token Revocation: unchecked
- Token Lifetime:
Click Show Advanced Fields and confirm the defaults match the following values. In particular, the Authorization Details Claim Name must match
authorization_detailsso PingFederate emits a populatedauthorization_detailsclaim for RAR requests.- Include Key ID Header Parameter: ✅ checked
- Include X.509 Thumbprint Header Parameter: unchecked
- Default JWKS URL Cache Duration:
720 - Include JWE Key ID Header Parameter: ✅ checked
- Include JWE X.509 Thumbprint Header Parameter: unchecked
- Client ID Claim Name:
client_id - Scope Claim Name:
scope - Space Delimit Scope Values: ✅ checked
- Authorization Details Claim Name:
authorization_details - Issuer Claim Value: (blank)
- Audience Claim Value: (blank)
- Not Before Claim Offset: (blank)
- Include Issued At Claim: ✅ checked
- JWT ID Claim Length:
22 - Access Grant GUID Claim Name: (blank)
- Publish Keys to PingFederate JWKS Endpoint: unchecked
- JWKS Endpoint Path: (blank)
- JWKS Endpoint Cache Duration:
720 - Publish Key ID X.509 URL: unchecked
- Publish Thumbprint X.509 URL: unchecked
- Expand Scope Groups: unchecked
- Type Header Value: (blank)
On the Session Validation tab, leave all four options unchecked.
Step 4: Define the allowed claims
Define the claims you want PingFederate to issue from your JWT access token manager.
The contract claims must include authorization_details to use RAR tokens.
Open the Applications page.
Click OAuth.
Select Access Token Management.
Choose Default.
Choose Access Token Attribute Contract.
Configure the contract with these attributes:

Leave the remaining fields set to the defaults and finish the JWT Access Token Manager setup.
Step 5: Configure the default client-credentials access-token mapping for RAR
Configure the client-credentials access-token mapping for the default JWT Access Token Manager.
The default access token manager is the RAR-capable token manager. It includes the authorization_details contract attribute.
Mapping the access tokens to a default manager allows PingFederate to issue client-credentials JWTs that can include a populated authorization_details claim when the RAR client supplies one in the token request.
Open the Applications page.
Select OAuth.
Select Access Token Mappings.
Set the Context to
Client Credentials.Set the Access token manager to
Default
In the Contract Fulfillment tab verify the following mappings:
- Contract:
authorization_details, Source:No Mapping - Contract:
client_id- Source:Context- Value:ClientId - Contract:
iss- Source:Text- Value:https://localhost:9031 - Contract:
sub- Source:Context- Value:ClientId
The
authorization_detailsis intentionally left asNo Mappinghere. For RAR, PingFederate populatesauthorization_detailsfrom the client-suppliedauthorization_detailsrequest parameter after configuring thevault:path_accessauthorization detail type and processor.
- Contract:
Leave all issuance criteria fields empty. Do not add a source, attribute, condition, value, or error result.
Click Next to continue to the Summary tab.
Confirm the mapping summary shows the following details:
- Context: Client Credentials
- Access token manager: Default
- Attribute Sources & User Lookup
- Leave Data Sources empty
- Contract Fulfillment
authorization_details:No Mappingclient_idmapped from Context toClientIdissmapped from Text to https://localhost:9031submapped from Context toClientId
- Issuance criteria:
(None)

Click Save.
Step 6: Create the OAuth clients and assign access token managers
Now create the OAuth client for vault-rar-client.
Navigate back to Applications.
Select OAuth.
Select Clients.
Select Add Client.
Name it
vault-rar-client.Set Client Authentication to Client Secret.
Set Allowed grant types to
Client Credentials.Set Default access token manager to
Default.Check Restrict to default access token manager.
Enable Authorization details and select
vault:path_accessafter creating the RAR type.Leave unrelated OIDC, redirect, refresh token, and consent settings at their defaults unless the flow requires them.
Save the CLIENT ID and CLIENT SECRET values for
vault-rar-client. You need the client values to validate the agent workflow later.$ export PING_CLIENT_ID="<your_client_ID>" \ PING_CLIENT_SECRET="<your_client_secret>"
Step 7: Enable vault:path_access on the RAR client
Open the Client Settings for
vault-rar-client.Set Grant Type to
Client Credentials.Set Access Token Manager to
Default.Check Restrict Scopes.
Check Allow Authorization Details.
Set Authorization Detail Type to
vault:path_access.Click Save.
Step 8: Save data for next steps
| Value | Environment variable | Description |
|---|---|---|
| Issuer URL | ISSUER | URL identifying your OIDC application |
| Key endpoint | JWKS_URI | URL where clients can download public keys (JWKS) |
| Certificate authority PEM file | CA_PEM | Local certificate authority file |
| Client ID for a OAuth client | PING_CLIENT_ID | ID for the OAuth client |
| Secret for OAuth Client | PING_CLIENT_SECRET | Client secret value created for the OIDC application |
| Token endpoint | TOKEN_ENDPOINT | OAuth endpoint URL for the OIDC application |
We recommend setting the following environment variables to make Vault configuration more convenient:
$ export \
VAULT_ADDR="<your_vault_server_url>" \
VAULT_TOKEN="<token_string>" \
JWKS_URI="https://localhost:9031/pf/JWKS" \
CA_PEM="<local valid CA cert>" \
ISSUER="<issuer_url>" \
PING_CLIENT_ID="<client_id>" \
PING_CLIENT_SECRET="<client_secret>"
TOKEN_ENDPOINT="<token_endpoint>"
For example:
$ export \
VAULT_ADDR="http://127.0.0.1:8200" \
VAULT_TOKEN="root" \
JWKS_URI="https://localhost:9031/pf/JWKS" \
CA_PEM=$(cat certs/pingfederate-localhost/pf-local-ca.crt) \
ISSUER="https://localhost:9031" \
PING_CLIENT_ID="vault-rar-client" \
PING_CLIENT_SECRET="00ZP/yBawx69XXXXxXXXqwY0XxXXXxXXxxM3mAGb501Ds/XSuqJInbaT4S6T2L" \
TOKEN_ENDPOINT="https://localhost:9031/as/token.oauth2"
Next steps
- Configure Vault to secure agentic workflows
- Configure Vault to secure OBO workflows
- Configure additional identity providers and authentication servers: