Document toolboxDocument toolbox

Google as an identity provider

After enabling Devo as a service provider, you can set up Google as an identity provider for SAML SSO.

To activate Google as an identity provider for SAML authorization, you need a Google administrator account.

  1. Log in to the Google Admin console and click Apps, then select SAML apps.

  2. Click the + icon in the bottom right corner of the screen to create a new SAML application.

  3. The first window in the setup process appears. Select Setup my own custom app.

  4. The next window displays the Google SSO URL, Entity ID, and Certificate. Copy the SSO URL and Entity ID, and download the Certificate for use later. 

  5. In the Devo Platform, go to Preferences → Domain preferences → Authentication. Paste the SSO URL and Entity ID into the corresponding fields of the Identity Provider area.

  6. Return to the Google process and click Next. In the following window, enter an Application Name (for example, SAML2 Devo access) and a Description for your custom SAML app and click Next.

  7. The Service Provider Details window appears. Return to the Devo Platform, copy the Home URL, ACS URL and Entity ID from the Service Provider area and paste them into the corresponding fields of the Google Admin console. 

  8. Select Basic information and Primary Email in the Name ID field of the Google Admin console. The Name ID Format field must match the one selected in Devo (by default UNSPECIFIED). Click Next.

  9. Click Finish in the next window. Then, to activate the newly created SAML app, click the ellipsis icon and select ON for everyone. 

  10. Finally, open the previously downloaded certificate using a text editor, then copy its content and paste it into the Add certificate field in Devo.

  11. Click Update to finish the process.