Google Workspace SSO
Use Google Workspace as your identity provider with OIDC or SAML, then add your Workspace domains in Avaloi.
Use Google as the identity provider for your company domain. OIDC is the usual path. SAML works if you already run it. Only the Owner can save the connection.
Connect Google Workspace
- Open the Admin console. Go to Apps, then Web and mobile apps for SAML, or to Google Cloud credentials for OIDC.
- Create the app. For SAML, add a custom SAML app with ACS
https://api.avaloi.com/auth/saml/{company}/acsand entity starthttps://api.avaloi.com/auth/saml/{company}/start. For OIDC, create an OAuth client and use the issuerhttps://accounts.google.com. - Assign users. Turn the app on for the organizational units that should reach Avaloi.
- Save in Avaloi. Open Company settings, then SSO. Paste the issuer or metadata URL, add your Workspace domains, and save.
- Test, then enforce. Sign in with a Workspace user. When that works, turn on Enforce SSO.
Avaloi links just-in-time users on the verified Workspace email.
Quick answers
Which issuer do I paste for OIDC?
https://accounts.google.com.
Can I add more than one Workspace domain? Yes. Add every domain you claim under SSO.
A user from another domain cannot sign in through Google. Only members on the claimed domains go through the provider. Add the domain, or let them sign in another way while SSO is not enforced.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.