Skip to main content

How do I set up SSO with Google Workspace?

Learn how to connect Google Workspace to Marvia with Single Sign-On (SSO).

Written by Maarten Peters

This guide is for Google Workspace administrators. Replace {your-portal-domain} with your Marvia portal host, for example acme.getmarvia.com. Marvia connects to Google Workspace using SAML 2.0. OpenID Connect is not used for this integration.


Create a Custom SAML App in Google Workspace, then send Marvia the values listed at the end of this page. After we save them, users can sign in with the SSO button on your Marvia login page.
​

1. Create the SAML App

  1. In the Google Admin Console (admin.google.com), go to Apps → Web and mobile apps.

  2. Click Add App → Add custom SAML app.

  3. Enter an App name, for example Marvia.

  4. (Optional) Add a description and upload the Marvia logo, then click Continue.
    ​

2. Configure SAML Settings

  1. On the Google Identity Provider details step, click Continue (you will collect the provider details in Step 5).

  2. On the Service provider details step, enter these values:

Google field

Value

ACS URL

https://{your-portal-domain}/saml/acs

Entity ID

https://{your-portal-domain}/saml/metadata

Start URL

https://{your-portal-domain}/login

Signed Response

Checked

Name ID format

EMAIL

Name ID

Basic Information > Primary email

(Optional) You can also click Optionally parse metadata and import Marvia's metadata from: https://{your-portal-domain}/saml/metadata
​

Click Continue.

3. Attribute Mapping

Map the standard user attributes in Google Workspace to Marvia:

  1. Under Attributes, click Add mapping.

  2. Configure the following custom attribute fields:

Google Workspace attribute

App attribute

Basic Information > First name

firstName

Basic Information > Last name

lastName

Basic Information > Primary email

email

Groups (optional)

If users should be placed in Marvia groups automatically:

  1. Under Group membership, click Add mapping.

  2. Select the Google Workspace groups that should sync.

  3. Set the App attribute name to groups.
    ​

Locations (optional)

If you use location or branch access in Marvia, add:

Google Workspace attribute

App attribute

Select the attribute containing the location (e.g., Employee details > Building ID or a custom attribute)

locations

Click Finish.
​

4. Turn On Access for Users

By default, newly created SAML apps are turned off for all users.

  1. In the app overview page, select User access.

  2. Select the Organizational Unit (OU) or group you want to grant access to.

  3. Change Service status to ON for everyone (or ON for selected OUs).

  4. Click Save.

5. Send these values to Marvia

Return to the app's Google Identity Provider details page (or click Download Metadata from the app overview) and send Marvia:

  • Entity ID (Identity Provider Issuer)

  • SSO URL (Identity Provider Single Sign-On URL)

  • Certificate: Download the Certificate, open it in a text editor, and copy the full text including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines.

Once we have saved these on our side, users can sign in with the SSO button on your Marvia login page.

Did this answer your question?