Google Workspace SAML SSO setup
Use this page when your IT team is creating a Google Workspace custom SAML app for Artifactive. Your Artifactive dashboard shows the setup values for your tenant, and we can help if your team wants an assisted setup.
How setup works
- Artifactive provides service-provider values in the dashboard.
- Your Google Workspace admin creates a custom SAML app.
- Your Google Workspace admin enters the Artifactive ACS URL and Entity ID.
- Your Google Workspace admin sets Name ID to the user's primary email.
- Your Google Workspace admin turns app access on for the users or organizational units that should have access.
- Artifactive records the Google identity-provider metadata.
- An Owner runs Test SSO in Artifactive before enabling SSO-only access.
Values from Artifactive
| Value | How it is used |
|---|---|
| ACS URL | Paste this into Google Workspace as the ACS URL. |
| Entity ID | Paste this into Google Workspace as the Entity ID. |
| Name ID format | Use email address if Google Workspace asks. |
| Name ID | Use the user's primary email. |
| Start URL | Leave blank unless Artifactive provides one. |
Values from your identity provider
- Google identity-provider metadata URL or metadata XML, if available.
- Google Entity ID / Issuer.
- Google SSO URL.
- Google x.509 signing certificate.
- Users or organizational units with app access turned on.
Google Workspace notes
- Create a custom SAML app in Google Workspace.
- Use the Artifactive ACS URL as the Google ACS URL.
- Use the Artifactive Entity ID as the Google Entity ID.
- Set Name ID to primary email.
- Turn app access on for the users or organizational units that should open Artifactive dashboards.
Testing before enforcement
- Run Test SSO from Artifactive.
- Test with an assigned user on an approved company email domain.
- Do not switch to SSO-only until the test passes.
- For team SSO-only, confirm Owner access and recovery before enforcing it.
Common setup issues
- User is not assigned to the SAML app.
- ACS URL or Entity ID does not exactly match.
- NameID/email is missing or not the user's work email.
- Metadata or signing certificate changed after setup.
- Google app access is not turned on for the user or organizational unit.