> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML with Google Identity

> Configure SAML single sign-on to Gumloop with Google Identity

Some companies use Google Identity for SAML single sign-on. Please note that SAML single sign-on via Google Identity differs from "Sign in with Google," which uses the [OAuth protocol](https://datatracker.ietf.org/doc/html/rfc6749) and is available on Gumloop out of the box.

<Warning>Before proceeding, please confirm that you indeed need SAML single sign-on via Google rather than "Sign in with Google".</Warning>

## Before you start: get your SP details from Gumloop

A Gumloop organization admin generates an SSO setup link at [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso) (see [SSO, SAML & SCIM](/enterprise-features/sso_saml_scim)). The setup page shows the two Service Provider values you'll copy into Google:

* **Assertion Consumer Service (ACS) URL** — ends in `/acs`
* **SP Entity ID** — the same URL without the `/acs` suffix

The same page has the fields for the values Google produces: **Redirect URL**, **IDP Entity ID**, and the **Certificate** upload.

<Steps>
  ### Creating a custom SAML app in Google Identity

  Starting from the Google Workspace admin page, i.e. [admin.google.com](https://admin.google.com), navigate to *Apps* > *Web and mobile apps* in the left navigation bar. This link will send you to a new page.

  <Frame caption="Selecting Apps > Web and mobile apps in the Google Workspace admin console">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google0.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=92f71329597c236e7bf15832885ed265" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google0.png" />
  </Frame>

  You'll land on a page with the header *Apps* > *Web and mobile apps*. Right under the header, you'll see a few tabs. Click *Add app* > *Add custom SAML app*. This link will send you to another new page.

  <Frame caption="Navigating to Add app > Add custom SAML app">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google1.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=8aeaf6d541dad92020a340b330bfa1c8" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google1.png" />
  </Frame>

  You'll see a page with a large blue header reading *Add custom SAML app*. This page requires you to assign the application an *App name*. The *App name* matters solely for display purposes — write "Gumloop".

  After typing the *App name*, hit the blue *CONTINUE* button in the lower right.

  <Frame caption="Naming the application">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google2.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=ae3bc3783892fd9f0d278623e16af708" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google2.png" />
  </Frame>

  ### Enter Google details in Gumloop

  Clicking *CONTINUE* in the previous step will direct you to a new page, again with the same blue header.

  <Info>The previous page enumerated a few steps directly below its header. It's totally normal for those to have disappeared. You're likely still on the right track. Scroll up on this page to display the steps again.</Info>

  Here, you'll find a few important details about the new Google Identity app that Gumloop needs to know about. Copy each of these from Google into your Gumloop SSO setup page.

  First, scroll down to the field marked *SSO URL*. Gumloop calls this the *Redirect URL*. Copy this URL from Google and paste it into Gumloop.

  <Frame caption="Copying Google's 'SSO URL' and pasting into Gumloop as the 'Redirect URL'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google3.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=66c4f0c06e53acc141037079a025aeea" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google3.png" />
  </Frame>

  From here, direct your attention to Google's *Entity ID* field. It sits directly under the *SSO URL* from the previous step.

  Copy this *Entity ID* URL and paste it into Gumloop as the *IDP Entity ID*. You'll find the input field for the *IDP Entity ID* adjacent to the *Redirect URL* input field from the previous step.

  <Frame caption="Copying Google's 'Entity ID' and pasting into Gumloop as the 'IDP Entity ID'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google3b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=219efe59aca07806e2f085de0d3594fc" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google3b.png" />
  </Frame>

  You need just one more detail from Google.

  Navigate to the next field marked *Certificate*. Then, toward the top right corner of this *Certificate* field, you'll see a download icon. Press the download icon; doing so downloads a `.pem` file. Its name will match the header you see here, something starting with `Google` and ending in `SAML2_0`.

  Upload this `.pem` file on your Gumloop SSO setup page as the *Certificate*.

  <Frame caption="Downloading a .pem certificate from Google and uploading it to Gumloop">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google3b-1.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=351175ccef675a078f34dbea8944049e" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google3b-1.png" />
  </Frame>

  Once you're done with this step, Gumloop has all the information it needs. Now you simply need to supply Google with the relevant information about Gumloop.

  A blue *CONTINUE* button sits toward the bottom right of the page. It may not be visible until you scroll down. Press this *CONTINUE* button.

  ### Enter Gumloop details in Google

  Once Gumloop knows about the Google app you've created, you need to tell Google about Gumloop. Google needs two pieces of information.

  First, Google asks for an *ACS URL*. Gumloop calls this the *Assertion Consumer Service (ACS) URL*, shown on your Gumloop SSO setup page. It ends in `/acs`.

  Copy this *Assertion Consumer Service (ACS) URL* and paste it into Google's *ACS URL* input field.

  <Frame caption="Gumloop's 'Assertion Consumer Service (ACS) URL' equates to Google's 'ACS URL'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google4.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=9a864f349f98ec0c9ca4c212dbcfc35e" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google4.png" />
  </Frame>

  You'll follow a similar pattern for an additional field.

  Directly below its *ACS URL* field, Google asks for an *Entity ID*. Gumloop calls this the *SP Entity ID*. You'll find this URL right next to the *Assertion Consumer Service (ACS) URL* on the setup page. The *SP Entity ID* looks exactly like the *Assertion Consumer Service (ACS) URL*, only it lacks the `/acs` ending.

  Copy the *SP Entity ID* from Gumloop and enter it as the *Entity ID* in Google.

  <Frame caption="Gumloop's 'SP Entity ID' equates to Google's 'Entity ID'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google4b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=26aca1b54db4b7af5fd1cdc99284018d" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google4b.png" />
  </Frame>

  Click the blue *CONTINUE* button in the lower right corner.

  <Frame caption="Press 'CONTINUE' to complete the SAML app configuration">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/google/google5.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=317892bc378609c7ca25ac9d8e4254c6" width="1920" height="1080" data-path="images/idp-guides/idp-assets/google/google5.png" />
  </Frame>

  Once you've completed this step, you're done! Gumloop is now hooked up to your Google Identity instance.

  Please note that users cannot successfully log in until a Google Identity administrator assigns them to the application.
</Steps>
