Skip to main content

Set up SSO with Google Workspace

Use Google Workspace as an identity provider for Circleback

You can connect Google Workspace to Circleback by creating a custom SAML app in the Google Workspace Admin Console.

You need access to manage apps in Google Admin and to be an admin of your Circleback workspace.

1. In Circleback, go to Settings → General (under Workspace).

2. Under Single sign-on, select Connect. Choose SAML, then select Continue. Keep this form open.

3. In another tab, open the Google Admin console and go to AppsWeb and mobile apps.

4. Select Add appAdd custom SAML app.

Google Admin: Add custom SAML app

5. Enter Circleback as the app name, then select Continue.

Google Admin: enter an app name

6. On the Google identity provider details page, select Download Metadata.

7. In Circleback, under Metadata source, choose Upload XML file and upload the file you downloaded.

8. Return to Google Admin and select Continue.

Google Admin: download identity provider metadata

9. Copy the ACS URL and Entity ID from the open Circleback form into Google's Service provider details page, and set the Name ID fields as shown below:

Field

Value

ACS URL

https://circleback.ai/api/sso/oauth/saml

Entity ID

https://circleback.ai/api/sso/metadata

Name ID format

EMAIL

Name ID

Basic Information → Primary email

10. Select Continue, then add these attribute mappings:

Google Directory attribute

App attribute

Primary email

email

First name

firstName

Last name

lastName

Google Admin: email and name attribute mappings

11. Select Finish.

12. Open the Circleback app in Google Admin and select User access.

Google Admin: open User access

13. Turn the service on for everyone or for the organizational units that should use Circleback.

14. Select Save.

Google Admin: turn the service on for your team

15. Return to the open Circleback form and select Continue. Leave No directory sync selected, then select Connect.

To require everyone in your workspace to log in with SSO, follow Enforce SSO for your workspace.

This setup connects sign-in, not SCIM provisioning. To revoke someone's workspace access, deactivate the member in Circleback.

Did this answer your question?