Skip to main content

Add Google Workspace as a SAML provider

This guide explains how to let users sign in to Casdoor with their Google Workspace account through SAML.


Learning outcomes​

  • Create a custom SAML app for Casdoor in Google Workspace.
  • Add Google Workspace as a SAML provider in Casdoor.

What you need​

  • Administrator access to the Google Admin console
  • Administrator access to the Casdoor admin console

Create a SAML app in Google Workspace​

  1. In the Google Admin console (admin.google.com), go to Apps > Web and mobile apps.

  2. Click Add App > Add custom SAML app.

  3. Enter an App name, for example Casdoor, and optionally an icon. Click Continue.

  4. Download the metadata, or note the SSO URL, the Entity ID, and the Certificate. Click Continue.

  5. Enter the service provider details:

    FieldValue
    ACS URLhttps://<your-casdoor-domain>/api/acs, for example https://door.example.com/api/acs
    Entity IDThe same URL
    Name ID formatEMAIL
    Name IDBasic Information > Primary email

    Google Workspace sends the response with HTTP POST, which the /api/acs endpoint requires. Click Continue.

  6. Optionally, map attributes, for example email to Primary email, and displayName to First name and Last name. Click Finish.

  7. Turn the app ON for your organization or for the organizational units that may sign in.

Add the provider in Casdoor​

  1. In the Casdoor admin console, go to Identity > Providers and add a provider.
  2. Set Category to SAML and Type to Custom.
  3. Paste the metadata from Google Workspace into Metadata and click Parse.
  4. Check that SP ACS URL and SP Entity ID are https://<your-casdoor-domain>/api/acs, and save the provider.
  5. Open the edit page of your application, add the provider on the Providers tab, and save.

Verify the result​

Open the sign-in page of the application and click the Google Workspace button.

See also​