PingOne's management API lives at https://api.pingone.com/v1 (.eu, .ca, .asia for other regions). Paths are scoped to an environment id. Get a token from a worker app first.
Create a Worker application in the PingOne admin console. The token call sends its client id and secret as Basic auth (-u, PostTaco's Auth tab); the returned access_token is {{PINGONE_TOKEN}}.
Full reference: https://apidocs.pingidentity.com/pingone/platform/v1/api/
curl -X POST https://auth.pingone.com/{{ENV_ID}}/as/token \
-u {{PINGONE_CLIENT_ID}}:{{PINGONE_CLIENT_SECRET}} \
-H "Content-Type: application/x-www-form-urlencoded" \
-d grant_type=client_credentials
curl "https://api.pingone.com/v1/environments/{{ENV_ID}}/users?limit=10" \
-H "Authorization: Bearer {{PINGONE_TOKEN}}"
curl https://api.pingone.com/v1/environments/{{ENV_ID}}/groups \
-H "Authorization: Bearer {{PINGONE_TOKEN}}"