Set Up SSO for Google Workspace
Connect Google Workspace as an SSO identity provider so your team signs in to Haystack Enterprise Platform with their Google Workspace accounts.
About This Task
Google Workspace connects through OIDC. For the email-claim, discovery-document, and client-secret requirements, see Set Up OIDC.
Prerequisites
Before you start, review the requirements and preconditions in Enable Single Sign-On (SSO).
Set Up the Connection
- In Haystack Enterprise Platform, go to Settings > Organization > SSO and click Add SSO connection.
- Select Google Workspace.
- Type a display name for the connection, for example
Google Workspace. The display name must be unique in your organization. - Create an OAuth 2.0 client ID and secret in the Google Cloud console, then paste them into the Client ID and Client secret fields. The secret is stored encrypted and never shown again. For details, see Manage OAuth apps in Google Cloud.
Once you've filled in the provider-specific fields, finish and test the connection:
- Add your corporate domains to the Email domains field. At least one domain is required.
- Click the toggle to enable the connection.
- Click Test connection to check that your provider's endpoint exists and responds. A successful connection means the address is reachable, not that sign-in works. It doesn't verify credentials, certificates, or claim mappings.
- Click Save.
Verify the Connection
To confirm your SSO connection works end to end, check the following:
- You have invited the pilot user to Haystack Enterprise Platform, and their email matches what your provider sends.
- The pilot user is assigned to the application in your provider.
- When you open Haystack Enterprise Platform in a private browsing window and enter the pilot user's email address, you're redirected to your provider, and after authenticating, you land back in Haystack Enterprise Platform, signed in.
- You repeated the process with a different browser to confirm.
What To Do Next
Was this page helpful?