Skip to main content
This documentation is for Passwork version 6.0, no longer supported.

See documentation for version 7.0.
Version: 6.0

Configuring SSO with Google

warning

Before performing SSO configuration, make sure that the value of the domain parameter in the config.ini configuration file is the current domain name of the Passwork server.

This is necessary so that IDP can download the https://<your-passwork>/sso/metadata file from your server. Your server must be configured to run over HTTPS protocol.

Example parameter in config.ini: domain = https://passwork.example.com

Go to AppsWeb and mobile apps in Google Admin Console.

Searching password by browser extension
Searching password by browser extension

Click Add app and choose Add custom SAML app.

Searching password by browser extension

Enter the name for your app and click Continue.

Searching password by browser extension

Go to** Passwork account settings**, open SSO settings and toggle SSO on:

Searching password by browser extension

Copy the SAML certificate and paste it into the corresponding field in Passwork settings:

Searching password by browser extension
Searching password by browser extension

Likewise, copy and paste the following fields into Passwork:

Searching password by browser extension
Searching password by browser extension

Copy the following fields from Passwork into Service provider details fields in Google Workspace:

Searching password by browser extension
Searching password by browser extension

Skip the Attribute mapping step and click Finish

Searching password by browser extension

On the page of the app you created, set the access to ON for everyone or use organizational groups to manage access.

Searching password by browser extension
info

Only whitelisted users will be aple to authenticate in the app

Click SSO Login on Passwork's authorization page and test the configuration.

Searching password by browser extension
info

You may encounter the app_not_configured_for_user error even if a user was whitelisted, since updating permissions in Google takes some time.