How can we help? 👋

How to set up SSO with Google Workspace

Step-by-step setup of the CheckHub SAML application in Google Workspace

This article shows you how to create the CheckHub SAML application in your Google Workspace account.

Before you start, make sure you have received the ACS URL and Entity ID from CheckHub. If you haven't, read "How to set up Single Sign-On (SSO) for your team" first.

Create the application

  1. Sign in to the Google Admin console.
  1. Go to Apps > Web and mobile apps > Add app > Add custom SAML app.
  1. Name it CheckHub, optionally add your logo, and click Continue.

Copy Google's details

  1. On the Google Identity Provider details screen, choose Option 2 and copy the SSO URL and the Entity ID, then click Download to save the certificate.
  1. Click Continue.

Keep all three — you'll send them to CheckHub at the end.

Notion image

Add the CheckHub details

On the Service provider details screen, fill in:

Field in Google Workspace
What to enter
ACS URL
Your ACS URL from CheckHub
Entity ID
Your Entity ID from CheckHub
Start URL
Leave empty
Signed response
Leave unchecked
Name ID format
EMAIL
Name ID
Basic Information > Primary email

Copy both values exactly as we sent them, including the ?connection=... part at the end of the ACS URL. Dropping it is the most common reason a first login fails.

Then click Continue.

Notion image

Map your users and groups

The Attribute mapping screen comes next. It carries two sections: Attributes at the top, and Group membership (optional) below it. The claim names and the group rules are the same for every provider, so they have their own article:

Map user attributes and groups for SSO — follow it for this screen, then come back here.

Notion image

Turn the app on

Once the app is created, open it and go to User access. Turn the service ON for the organizational units or groups that should be able to use CheckHub.

Only these people can log in, which also makes this the quickest way to remove someone's access later.

Notion image

Send us your details

Send the SSO URLEntity ID and certificate you copied earlier to your CheckHub contact. The certificate is a public certificate, so it's safe to send by email — we will never ask you for a private key or a password.

We'll confirm when the connection is ready to test.

💡

Google can take up to 24 hours to publish a new SAML app, though it's usually much faster. If your very first test login fails right after setup, wait a little and try again before you start troubleshooting.

Want to know more?

Did this answer your question?
😞
😐
🤩