This article shows you how to create the CheckHub SAML application in your Google Workspace account.
Before you start, make sure you have received the ACS URL and Entity ID from CheckHub. If you haven't, read "How to set up Single Sign-On (SSO) for your team" first.
Create the application
- Sign in to the Google Admin console.
- Go to Apps > Web and mobile apps > Add app > Add custom SAML app.
- Name it
CheckHub, optionally add your logo, and click Continue.
Copy Google's details
- On the Google Identity Provider details screen, choose Option 2 and copy the SSO URL and the Entity ID, then click Download to save the certificate.
- Click Continue.
Keep all three — you'll send them to CheckHub at the end.

Add the CheckHub details
On the Service provider details screen, fill in:
Field in Google Workspace | What to enter |
ACS URL | Your ACS URL from CheckHub |
Entity ID | Your Entity ID from CheckHub |
Start URL | Leave empty |
Signed response | Leave unchecked |
Name ID format | EMAIL |
Name ID | Basic Information > Primary email |
Copy both values exactly as we sent them, including the ?connection=... part at the end of the ACS URL. Dropping it is the most common reason a first login fails.
Then click Continue.

Map your users and groups
The Attribute mapping screen comes next. It carries two sections: Attributes at the top, and Group membership (optional) below it. The claim names and the group rules are the same for every provider, so they have their own article:
Map user attributes and groups for SSO — follow it for this screen, then come back here.

Turn the app on
Once the app is created, open it and go to User access. Turn the service ON for the organizational units or groups that should be able to use CheckHub.
Only these people can log in, which also makes this the quickest way to remove someone's access later.

Send us your details
Send the SSO URL, Entity ID and certificate you copied earlier to your CheckHub contact. The certificate is a public certificate, so it's safe to send by email — we will never ask you for a private key or a password.
We'll confirm when the connection is ready to test.
Google can take up to 24 hours to publish a new SAML app, though it's usually much faster. If your very first test login fails right after setup, wait a little and try again before you start troubleshooting.
Want to know more?
- Troubleshoot and maintain your SSO connection — including how to renew your certificate before it expires
