Set up single sign-on with Google Workspace

Table of Contents

Agents then sign in to Taiwa with their Google Workspace account. You need a Google Workspace account that can create a project in the Google Cloud console, and the administrator role in Taiwa.

Before you start

  • Ask Taiwa to verify the email domains of your organisation. All Google accounts share one issuer, so the verified domains are what keep Taiwa to your organisation: Taiwa refuses a sign-in from any other domain.

1. Set up Google Auth Platform

  1. Sign in to the Google Cloud console with your Google Workspace account.
  2. Select a project, or create one, for example Taiwa sign-in.
  3. Go to Google Auth Platform. If Google asks you to set it up, enter an app name, for example Taiwa, and a support email address.
  4. Under Audience, set the User type to Internal. Only people in your organisation can then sign in with this client.

Taiwa asks only for the scopes openid, email and profile. Google needs no verification of the app for these scopes.

2. Create the OAuth client

  1. Under Clients, select Create client.
  2. For Application type, select Web application, and enter a name, for example Taiwa.
  3. Under Authorized redirect URIs, select Add URI, and enter https://api.taiwa.cx/v1/auth/sso/callback.
  4. Select Create.
  5. Copy the Client ID and the Client secret at once. Google shows the secret only when you create the client.

3. Connect Google in the admin portal

  1. In the admin portal, open SSO & Provisioning.
  2. For Issuer URL, enter https://accounts.google.com.
  3. For Client ID and Client secret, enter the values from Google.
  4. Select Save connection.

4. Test

Sign in to the admin portal in a private browser window. Select Sign in with SSO, enter your Organisation ID, and sign in with a Google account of your organisation.

Users

Google Workspace cannot sync users to Taiwa with SCIM. Add people in one of these ways:

  • Invite them from the Users tab.
  • Let them sign in with SSO. Taiwa creates the user at the first sign-in when the email domain is verified.

To remove someone, deactivate the user in Taiwa as well as in Google Workspace.

If sign-in fails

When a sign-in fails after the identity provider, the browser shows a page on api.taiwa.cx with the reason. The reason is in English.

Reason What to check
Google says that access is blocked, or that the app is for a different organisation The User type is not Internal, or the person signs in with a Google account outside your organisation.
Google says that the redirect URI does not match The client must have https://api.taiwa.cx/v1/auth/sso/callback exactly under Authorized redirect URIs.
Email domain is not verified for this tenant Ask Taiwa to verify the domain.
SSO token exchange failed The client secret is wrong. Make a new secret for the client and update the connection.
Was this helpful?