Integrate Devin with Live PingOne Data Using CData Connect AI
Devin is an AI software engineer from Cognition that plans, writes, and tests code in autonomous sessions. It supports the model context protocol (MCP) through its built-in MCP marketplace, allowing you to install remote MCP servers and give Devin access to external tools and live data sources.
By integrating Devin with CData Connect AI through the built-in MCP Server, Devin gains governed, real-time access to live PingOne data. You can list catalogs, explore schemas, and query records from PingOne data using natural language prompts, with all data access running securely against authorized sources.
This article explains how to configure PingOne connectivity in Connect AI, install the CData Connect AI MCP Server from the Devin MCP marketplace, and verify the integration by querying live PingOne data from a Devin session.
Step 1: Configure PingOne connectivity for Devin
Connectivity to PingOne from Devin is made possible through Connect AI's Remote MCP Server. To interact with PingOne data from Devin, start by creating and configuring a PingOne connection in Connect AI.
- Log into Connect AI, click Sources, and then click Add Connection
- Select PingOne from the Add Connection panel
-
Enter the necessary authentication properties to connect to PingOne.
To connect to PingOne, configure these properties:
- Region: The region where the data for your PingOne organization is being hosted.
- AuthScheme: The type of authentication to use when connecting to PingOne.
- Either WorkerAppEnvironmentId (required when using the default PingOne domain) or AuthorizationServerURL, configured as described below.
Configuring WorkerAppEnvironmentId
WorkerAppEnvironmentId is the ID of the PingOne environment in which your Worker application resides. This parameter is used only when the environment is using the default PingOne domain (auth.pingone). It is configured after you have created the custom OAuth application you will use to authenticate to PingOne, as described in Creating a Custom OAuth Application in the Help documentation.
First, find the value for this property:
- From the home page of your PingOne organization, move to the navigation sidebar and click Environments.
- Find the environment in which you have created your custom OAuth/Worker application (usually Administrators), and click Manage Environment. The environment's home page displays.
- In the environment's home page navigation sidebar, click Applications.
- Find your OAuth or Worker application details in the list.
-
Copy the value in the Environment ID field.
It should look similar to:
WorkerAppEnvironmentId='11e96fc7-aa4d-4a60-8196-9acf91424eca'
Now set WorkerAppEnvironmentId to the value of the Environment ID field.
Configuring AuthorizationServerURL
AuthorizationServerURL is the base URL of the PingOne authorization server for the environment where your application is located. This property is only used when you have set up a custom domain for the environment, as described in the PingOne platform API documentation. See Custom Domains.
Authenticating to PingOne with OAuth
PingOne supports both OAuth and OAuthClient authentication. In addition to performing the configuration steps described above, there are two more steps to complete to support OAuth or OAuthCliet authentication:
- Create and configure a custom OAuth application, as described in Creating a Custom OAuth Application in the Help documentation.
- To ensure that the driver can access the entities in Data Model, confirm that you have configured the correct roles for the admin user/worker application you will be using, as described in Administrator Roles in the Help documentation.
- Set the appropriate properties for the authscheme and authflow of your choice, as described in the following subsections.
OAuth (Authorization Code grant)
Set AuthScheme to OAuth.
Desktop Applications
Get and Refresh the OAuth Access Token
After setting the following, you are ready to connect:
- InitiateOAuth: GETANDREFRESH. To avoid the need to repeat the OAuth exchange and manually setting the OAuthAccessToken each time you connect, use InitiateOAuth.
- OAuthClientId: The Client ID you obtained when you created your custom OAuth application.
- OAuthClientSecret: The Client Secret you obtained when you created your custom OAuth application.
- CallbackURL: The redirect URI you defined when you registered your custom OAuth application. For example: https://localhost:3333
When you connect, the driver opens PingOne's OAuth endpoint in your default browser. Log in and grant permissions to the application. The driver then completes the OAuth process:
- The driver obtains an access token from PingOne and uses it to request data.
- The OAuth values are saved in the location specified in OAuthSettingsLocation, to be persisted across connections.
The driver refreshes the access token automatically when it expires.
For other OAuth methods, including Web Applications, Headless Machines, or Client Credentials Grant, refer to the Help documentation.
- Click Save & Test
- Navigate to the Permissions tab and update user-based permissions
With the PingOne connection configured, Devin can now connect to PingOne data through Connect AI.
Step 2: Install the Connect AI MCP Server in Devin
Next, install the CData Connect AI MCP Server from the Devin MCP servers list so your sessions can discover and call live data tools through Connect AI.
Note: Installing MCP servers in Devin requires the Manage MCP Servers permission. If you don't have this permission, use the Suggest option or contact your organization admin.
- Log into Devin and navigate to Settings and Connections, then select the MCP servers tab
- Search for CData Connect AI in the marketplace and select the verified listing
-
Click Install and enable. When prompted, complete the OAuth flow to authenticate with your Connect AI account
-
Once installed, confirm the Enable in sessions toggle is on and click Test tools. Devin validates the connection and lists the available Connect AI tools, such as getCatalogs, getSchemas, getTables, and queryData
With the MCP server installed and enabled, the Connect AI tools are available to every Devin session in your workspace.
Step 3: Query live PingOne data from Devin
With the integration complete, start a Devin session and interact with live PingOne data through natural language prompts.
- From the Devin home page, start a new session
-
In the session prompt, ask Devin to work with your Connect AI data, for example:
- Can you list the connections in CData Connect AI
- Show the available schemas and tables for PingOne
- Query the top 5 records from a table in PingOne
-
Devin calls the Connect AI MCP Server and returns live results from PingOne data directly in the session. You can follow the tool calls, inputs, and outputs in the Progress panel
At this point, Devin communicates with the Connect AI MCP Server and retrieves live PingOne data through remote MCP tools directly from your sessions, whether you're exploring data, building features against it, or automating engineering tasks.
Get started with CData Connect AI
To access hundreds of SaaS, big data, and NoSQL sources directly from your cloud applications, try CData Connect AI today. Download a free 14-day trial of CData Connect AI, and our Support Team is available to help with any questions you have.