Enabling single sign-on with SAML for Google Workspace

Requirements

  • Advanced Authentication & User Management
  • Global Robin Admin

Similar name, different systems

Google's SAML authentication is different from Google SSO, which uses the "Sign In with Google" button. Both let your users access Robin on their own, but SAML gives you more control.

Robin is a pre-configured application

Robin is one of Google's pre-integration SAML applications. You can skip most of this guide. The full steps stay here if you prefer to set it up by hand.

Set up SAML authentication for Robin with Google Workspace. Google Workspace can act as a SAML Identity Provider. If your organization does not use SAML yet, you can set up authentication without a third-party service such as Okta or OneLogin.

The steps are the same as for any custom provider, with screenshots for Google.

Find SAML Apps in Google

As an administrator on your Google account, go to the admin portal and select Apps > SAML Apps.

You see a list of your existing SAML apps. Select the large plus sign in the bottom right to add an app.

Add a service app

Select "Setup my own custom app" near the bottom of the window.

Google IDP Information

You see your Identity Provider information. You need the information in Option 1 to configure Robin later. Open a new browser window so you can see both.

Basic App Information

Name the SAML app and upload an icon so you can find it. Download the Robin icon below:

Robin SAML App Icon

Service Provider Details

Enter these service provider details:

  • ACS URL (Assertion Consumer Service): https://dashboard.robinpowered.com/sso/saml/custom
  • Entity ID: https://robinpowered.com
  • Start URL: Leave empty
  • Signed Response: Check this box
  • Name ID: Select "Basic Information" and "Primary Email"

Robin app config options for Google SAML

Attribute Mapping

In the last step, map 3 metadata attributes to your Google Workspace users. The names are case-sensitive:

  • Email: Basic Information > Primary Email
  • FirstName: Basic Information > First Name
  • LastName: Basic Information > Last Name

Add your IDP to Robin

As an administrator in the Robin dashboard, go to Manage > Integrations. Scroll down to Authentication methods to find the SAML SSO option.

2023-10-11_15-01-50.png

Select Add to open the configuration options. Leave "Custom" selected and paste in these fields:

  • SAML SSO URL: Use SSO URL
  • Identity Provider Issuer: Use Entity ID
  • Public Certificate: Use the certificate downloaded from Google in the previous step.

Save the form, then go back to Google Admin for the last step.

Turn on the app for everyone

The app does not work until you turn it on for your domain. Turn it on for everyone in your organization or for specific organizations.

When the app is on, Robin shows in everyone's app menu with your other SAML apps. If Robin is not in the menu, select "More" to see the full list of apps.

This link starts an IDP-initiated workflow. It opens your organization in Robin with the user signed in. First-time users complete a short registration step first.

A sample workflow

The image below shows a full SAML sign-in with Google and Robin.

Complete SAML auth with Google and Robin

Articles in this section

Was this article helpful?
2 out of 4 found this helpful
Share