Add Google Workspace as a SAML provider
This guide explains how to let users sign in to Casdoor with their Google Workspace account through SAML.
Learning outcomes
- Create a custom SAML app for Casdoor in Google Workspace.
- Add Google Workspace as a SAML provider in Casdoor.
What you need
- Administrator access to the Google Admin console
- Administrator access to the Casdoor admin console
Create a SAML app in Google Workspace
-
In the Google Admin console (admin.google.com), go to Apps > Web and mobile apps.
-
Click Add App > Add custom SAML app.
-
Enter an App name, for example
Casdoor, and optionally an icon. Click Continue. -
Download the metadata, or note the SSO URL, the Entity ID, and the Certificate. Click Continue.
-
Enter the service provider details:
Field Value ACS URL https://<your-casdoor-domain>/api/acs, for examplehttps://door.example.com/api/acsEntity ID The same URL Name ID format EMAILName ID Basic Information > Primary email Google Workspace sends the response with HTTP POST, which the
/api/acsendpoint requires. Click Continue. -
Optionally, map attributes, for example
emailto Primary email, anddisplayNameto First name and Last name. Click Finish. -
Turn the app ON for your organization or for the organizational units that may sign in.
Add the provider in Casdoor
- In the Casdoor admin console, go to Identity > Providers and add a provider.
- Set Category to
SAMLand Type toCustom. - Paste the metadata from Google Workspace into Metadata and click Parse.
- Check that SP ACS URL and SP Entity ID are
https://<your-casdoor-domain>/api/acs, and save the provider. - Open the edit page of your application, add the provider on the Providers tab, and save.
Verify the result
Open the sign-in page of the application and click the Google Workspace button.
See also
- SAML providers
- Connect Google Workspace with SAML: Casdoor as the IdP of Google Workspace.