Enabling single sign-on with SAML for Google Workspace

Requirements

  • Advanced Authentication and Security
  • Global Robin Admin

Set up SAML authentication for Robin with Google Workspace. Google Workspace can act as a SAML Identity Provider. If your organization does not use SAML yet, you can set up authentication without a third-party service such as Okta or OneLogin.

The steps are the same as for any custom provider, with the steps for Google.

Similar name, different systems

Google's SAML authentication is different from Google SSO, which uses the Continue with Google button. Both let your users access Robin on their own, but SAML gives you more control.

Robin is a pre-configured application

Robin is one of Google's pre-integration SAML applications. You can skip most of this guide. The full steps stay here if you prefer to set it up by hand.

Add Robin as a custom SAML app in Google

As a super administrator on your Google account, create a custom SAML app for Robin in the Google Admin console.

  1. Sign in to the Google Admin console.
  2. Go to Apps > Web and mobile apps.
  3. Select Add App > Add custom SAML app.
  4. Enter a name for the app, such as Robin. You can also upload an icon so you can find the app. Download the Robin icon.
  5. Select Continue. The Google Identity Provider details page opens.
  6. Keep these values. You need them to configure Robin later.
    • SSO URL: starts with https://accounts.google.com/o/saml2/idp?idpid=
    • Entity ID: starts with https://accounts.google.com/o/saml2?idpid=
    • Certificate: select Download to save it
  7. Select Continue.
  8. In Service Provider Details, enter these details:

    Field Value
    ACS URL (Assertion Consumer Service) https://dashboard.robinpowered.com/sso/saml/custom
    Entity ID https://robinpowered.com
    Start URL Leave empty
    Signed response Check this box
    Name ID Select Basic Information > Primary Email
  9. Select Continue.
  10. In Attribute Mapping, map 3 attributes to your Google Workspace users. For each one, select Add mapping, choose the field under Google Directory attributes, and enter the name under App attributes. The names are case-sensitive.

    App attribute Google Directory attribute
    Email Basic Information > Primary Email
    FirstName Basic Information > First Name
    LastName Basic Information > Last Name
  11. Select Finish.

Add your IDP to Robin

Copy the Google values into the SAML configuration form in the Robin dashboard.

  1. In the Robin dashboard, as an admin, go to Manage > Security. You can also go to Manage > Integrations and select Manage Sign-In Options.
  2. In the SAML 2.0 card, select Add. The SAML configuration form opens.
  3. Leave Provider set to Custom (Default) and paste in these fields:

    Robin field Google value
    SAML SSO URL SSO URL
    Identity Provider Issuer Entity ID
    Public Certificate The Certificate you downloaded from Google
  4. Select Save Configuration.

Turn on the app for everyone

The app does not work until you turn it on for your domain.

  1. In the Google Admin console, go to Apps > Web and mobile apps.
  2. Select the Robin app.
  3. Select User access.
  4. Select On for everyone, then select Save. To turn on the app for some organizational units only, select a unit and set Service status to On instead.

Google can take up to 24 hours to apply the change.

When the app is on, Robin shows in everyone's app menu with your other SAML apps. If Robin is not in the menu, select More to see the full list of apps.

This link starts an IDP-initiated workflow. It opens your organization in Robin with the user signed in. First-time users complete a short registration step first.

Articles in this section

Was this article helpful?
2 out of 4 found this helpful
Share