How to Connect PingOne Data to Gemini Enterprise via CData Connect AI
Gemini Enterprise is Google's enterprise AI assistant, available as part of Google Workspace. With native support for Custom MCP Server data stores, Gemini Enterprise can be extended to query and act on live enterprise data via the Model Context Protocol (MCP). When combined with CData Connect AI Remote MCP, Gemini Enterprise can interact with PingOne data in real time using natural language — without data replication or custom integration logic.
CData Connect AI offers a dedicated cloud-to-cloud interface for connecting to PingOne data via a single managed MCP endpoint. The CData Connect AI Remote MCP Server enables secure communication between Gemini Enterprise and PingOne, allowing users to ask questions and take actions on live PingOne data through natural language prompts.
This article explains how to connect Gemini Enterprise to live PingOne data through CData Connect AI by creating a Custom MCP Server data store — giving users access to PingOne data directly from the Gemini Enterprise chat interface.
Prerequisites
- A CData Connect AI account with at least one active connection (e.g., PingOne)
- A Gemini Enterprise account (trial available)
- A Google Cloud project with billing enabled
- The Google Cloud CLI installed and configured
- In your Google Cloud account:
- Override the organization policy for Custom MCP data stores (learn more).
- Grant the Discovery Engine Editor role to the administrator (learn more).
Step 1: Configure PingOne connectivity for Gemini Enterprise
Connectivity to PingOne from Gemini Enterprise is made possible through CData Connect AI Remote MCP. To interact with PingOne data from Gemini Enterprise, start by creating and configuring a PingOne connection in CData Connect AI.
- Log into Connect AI, click Sources, and then click Add Connection
- Select "PingOne" from the Add Connection panel
-
Enter the necessary authentication properties to connect to PingOne.
To connect to PingOne, configure these properties:
- Region: The region where the data for your PingOne organization is being hosted.
- AuthScheme: The type of authentication to use when connecting to PingOne.
- Either WorkerAppEnvironmentId (required when using the default PingOne domain) or AuthorizationServerURL, configured as described below.
Configuring WorkerAppEnvironmentId
WorkerAppEnvironmentId is the ID of the PingOne environment in which your Worker application resides. This parameter is used only when the environment is using the default PingOne domain (auth.pingone). It is configured after you have created the custom OAuth application you will use to authenticate to PingOne, as described in Creating a Custom OAuth Application in the Help documentation.
First, find the value for this property:
- From the home page of your PingOne organization, move to the navigation sidebar and click Environments.
- Find the environment in which you have created your custom OAuth/Worker application (usually Administrators), and click Manage Environment. The environment's home page displays.
- In the environment's home page navigation sidebar, click Applications.
- Find your OAuth or Worker application details in the list.
-
Copy the value in the Environment ID field.
It should look similar to:
WorkerAppEnvironmentId='11e96fc7-aa4d-4a60-8196-9acf91424eca'
Now set WorkerAppEnvironmentId to the value of the Environment ID field.
Configuring AuthorizationServerURL
AuthorizationServerURL is the base URL of the PingOne authorization server for the environment where your application is located. This property is only used when you have set up a custom domain for the environment, as described in the PingOne platform API documentation. See Custom Domains.
Authenticating to PingOne with OAuth
PingOne supports both OAuth and OAuthClient authentication. In addition to performing the configuration steps described above, there are two more steps to complete to support OAuth or OAuthCliet authentication:
- Create and configure a custom OAuth application, as described in Creating a Custom OAuth Application in the Help documentation.
- To ensure that the driver can access the entities in Data Model, confirm that you have configured the correct roles for the admin user/worker application you will be using, as described in Administrator Roles in the Help documentation.
- Set the appropriate properties for the authscheme and authflow of your choice, as described in the following subsections.
OAuth (Authorization Code grant)
Set AuthScheme to OAuth.
Desktop Applications
Get and Refresh the OAuth Access Token
After setting the following, you are ready to connect:
- InitiateOAuth: GETANDREFRESH. To avoid the need to repeat the OAuth exchange and manually setting the OAuthAccessToken each time you connect, use InitiateOAuth.
- OAuthClientId: The Client ID you obtained when you created your custom OAuth application.
- OAuthClientSecret: The Client Secret you obtained when you created your custom OAuth application.
- CallbackURL: The redirect URI you defined when you registered your custom OAuth application. For example: https://localhost:3333
When you connect, the driver opens PingOne's OAuth endpoint in your default browser. Log in and grant permissions to the application. The driver then completes the OAuth process:
- The driver obtains an access token from PingOne and uses it to request data.
- The OAuth values are saved in the location specified in OAuthSettingsLocation, to be persisted across connections.
The driver refreshes the access token automatically when it expires.
For other OAuth methods, including Web Applications, Headless Machines, or Client Credentials Grant, refer to the Help documentation.
- Click Save & Test
-
Navigate to the Permissions tab in the Add PingOne Connection page and update the User-based permissions.
Create an OAuth App in CData Connect AI
Gemini Enterprise uses OAuth 2.0 Authorization Code with PKCE to authenticate users against the CData Connect AI MCP Server. This requires creating a user-based OAuth App in your CData Connect AI account.
- Click the Gear icon () in the top-right corner of Connect AI to open Settings.
- Navigate to OAuth Apps and click + Create App. The Create OAuth App dialog appears.
- Enter the following settings:
- Name — Enter a descriptive name (e.g., GeminiEnterpriseOAuth).
- Authentication Flow — Select User-based (Authorization Code).
- Callback URL — Enter https://vertexaisearch.cloud.google.com/oauth-redirect.
- Click Confirm. CData Connect AI creates the OAuth App and generates a Client ID and Client Secret.
- Copy both the Client ID and Client Secret values. You will need them in Step 5.
With the connection configured and an OAuth App created, we are ready to create the custom MCP server data store in Gemini Enterprise.
Step 2: Create the custom MCP server data store
- Open Gemini Enterprise and navigate to the Data stores screen.
- Click Create data store.
- On the Select a data source page, enter Custom MCP Server in the Search sources field. The Custom MCP Server card displays.
- Click Add MCP server. The MCP Server Configuration page displays.
- In the Authentication settings section, enter values in the following required fields:
- MCP Server URL: https://mcp.cloud.cdata.com/mcp
- Authorization URL: https://cloud-login.cdata.com/authorize
- Token URL: https://cloud-login.cdata.com/oauth/token
- Client ID and Client Secret: From the OAuth App created in Step 1
- Click Login, and complete the sign-in.
- Click Continue, and the Advanced options section opens.
In the MCP Server Description field, enter a description that helps Gemini Enterprise understand what the server does and when to use it. For more information, see Write effective MCP server descriptions and instructions.
Click Continue.
In the Configure your data connector section, select the Location of your data connector from the Multi-region field list.
In Your data connector name, enter a name for your data store.
Click Create. Gemini Enterprise creates your data store and displays your data stores on the Data Stores page.
Note: By default, no tools or actions from your custom MCP servers are enabled. You must enable the tools or actions.
Step 3: Enable actions
After creating the custom MCP server data store, you must enable at least one tool or action before it can be used in Gemini Enterprise.
- Go to your custom MCP server data store.
Open the Actions tab and select Reload custom actions to reauthenticate.
Note: This action performs a tools/list call on the MCP server to retrieve available tools, which are then displayed on the screen.
- Select the actions to enable.
- Click Enable actions.
Step 4: Connect the MCP server data store to a Gemini Enterprise app
After creating the custom MCP server data store and enabling actions, you must connect the data store to a Gemini Enterprise app before it can be used.
- In the Google Cloud console, go to the Gemini Enterprise page.
- From the navigation menu, click Apps.
- Select the Gemini Enterprise app where you want to connect your data store.
- From the navigation menu of the app, click Connected data sources.
- Click Add existing data stores and select your data store.
- Click Connect.
Step 5: Query live PingOne data with natural language
With the data store connected, Gemini Enterprise users can interact with live PingOne data using natural language from the Gemini Enterprise web application. Each user authenticates with their own Connect AI credentials via the OAuth flow on first use.
- Open Gemini Enterprise, click Connections and authorize CData Connect AI.
-
Ask natural language questions about your PingOne data:
- "Show me all PingOne data from the last 30 days"
- "What are the top records in PingOne data by revenue?"
- "List all active PingOne data and their current status"
- "Summarize PingOne data activity for this quarter"
- The agent automatically discovers available connections in Connect AI, identifies the most relevant PingOne connection, generates SQL, and returns results — all without requiring the user to write queries or understand the underlying data structure.
Get CData Connect AI
To get live data access to hundreds of SaaS, Big Data, and NoSQL sources directly from Gemini Enterprise and other AI platforms, try CData Connect AI today!