Google Workspace SSO
Use Google Workspace as your identity provider with a custom SAML app, then add your Workspace domains in Avaloi.
Connect Google Workspace to Avaloi with SAML 2.0. Only the Owner can save the connection, and it is for Enterprise accounts. The full flow, including domain proof, testing, and mandatory sign-on, is in Single sign-on with SAML.
Connect Google Workspace
- Open the Admin console. Go to Apps, then Web and mobile apps, then Add app, then Add custom SAML app.
- Copy the Google details. On the Google Identity Provider details step, download the metadata, or copy the SSO URL, Entity ID, and certificate.
- Add the Avaloi details. Set the ACS URL and Entity ID from the Single sign-on page in Avaloi. Set Name ID format to EMAIL and Name ID to Basic Information, Primary email.
- Turn the app on for the organizational units that should reach Avaloi.
- In Avaloi, open Company settings, then Single sign-on, then Enable. Paste the metadata URL, list your email domains, and save.
- Add the DNS TXT record Avaloi shows under Domain proof, choose Verify domain, then choose Test connection.
- Sign in once through Sign in with your company. When that works, turn on Mandatory single sign-on if you want it.
Quick answers
Can I add more than one Workspace domain? Yes. List every domain you own under Single sign-on, and verify each with the TXT record.
Avaloi refused the response.
Check that the assertion is signed, that the email is the NameID or the email attribute, and that the email is on a domain you verified. See the fixes in Single sign-on with SAML.
Members are stuck in a loop. The Owner can always sign in with a password. Turn Mandatory single sign-on off, fix the connection, run Test connection, then turn it on again.
API
GET /v1/companies/me/sso/sp-metadataPUT /v1/companies/me/ssoPOST /v1/companies/me/sso/test
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.