SSO with Google
Integrate Google Workspace as the identity provider for Awell, using a custom SAML app.
With Google as the identity provider (IdP), people sign in to Awell with their Google credentials. The connection is a custom Security Assertion Markup Language (SAML) app in Google Workspace.
Before starting
- Google Workspace Admin Console access with administrative privileges.
- An Awell account with permission to configure single sign-on (SSO). Awell provides an ACS URL and an Entity ID on request.
Request SSO from Awell first; step 1 can't be completed without the ACS URL and Entity ID.
1. Set up a SAML app in Google Workspace
Google's own guides cover setting up a custom SAML app and configuring the SSO profile for the organization. Use the ACS URL and Entity ID Awell provided.
2. Gather the SAML configuration details from Google
Collect the details Google generates for the app, including its metadata.
3. Assign users in Google Workspace
Assign the app to the users and groups who should have Awell access.
Once SSO is live, this becomes the ongoing access process: granting Awell access means assigning someone here, and with just-in-time provisioning their Awell profile is created on first login.
4. Provide the Google metadata to Awell
Send the metadata to Awell, who complete the connection on their side.
Awell completes the connection
Awell finishes the configuration and confirms when SSO is live. Test with one user before assigning everyone.
Next steps
Once people can sign in, assign them the right roles. SSO controls who can log in, and roles control what they can do.