Set up single sign-on with Google Workspace
Tabs
FormCan connects to Google Workspace with SAML 2.0 through a custom SAML app. Members then sign in with their Workspace account and get a FormCan tile in the Google app launcher.
For an overview of the Single Sign-On page, see Single sign-on (SSO).
This guide is about single sign-on managed by your Workspace administrator. It is separate from the Google button on the FormCan login page, which any Google account can use.
Before you begin
- You are a Google Workspace super administrator.
- In FormCan, you are the team owner or a member with the Manage members access.
- In FormCan, open your team menu and select Single Sign-On. On the Connection tab, pick Google Workspace. Keep this page open: it shows the values Google needs, each with a Copy button.
In the Google Admin console
-
Go to Apps > Web and mobile apps, click Add app, then Add custom SAML app.
-
Enter an app name, for example
FormCan, and click Continue. -
On Google Identity Provider details, click Download metadata and keep the file. Click Continue.
-
On Service provider details, enter:
- ACS URL: the ACS URL from FormCan.
- Entity ID: the Entity ID from FormCan.
- Start URL: the Start URL from FormCan.
- Name ID format: EMAIL.
- Name ID: Basic Information > Primary email.
Click Continue.
-
On Attribute mapping, add:
Google directory attribute App attribute Primary email emailFirst name first_nameLast name last_nameClick Finish.
-
Open User access and turn the app ON for everyone, or for the organizational units that may sign in. Changes can take a few minutes to apply.
In FormCan
Google Workspace has no metadata URL, so you paste three values from the metadata file you downloaded. Open the file in a text editor.
-
Under 3. Values from your identity provider, fill in:
- Identity provider entity ID (issuer): the
entityIDof theEntityDescriptorelement. - Sign-on URL (HTTP-Redirect): the
Locationof theSingleSignOnServiceelement with the HTTP-Redirect binding. - Signing certificate: the text inside the
X509Certificateelement.
- Identity provider entity ID (issuer): the
-
Click Save connection.
Verify your domain, test and turn on
-
On the Email domains tab, add your Workspace domain, create the TXT record FormCan shows at your DNS provider, and click Verify.
-
In the status card, click Test connection. A window signs you in through Google and shows the email, name and attribute names FormCan received.
-
Click Turn on single sign-on.
Members can now click SSO on the FormCan login page, open the start URL, or use the FormCan tile in the Google app launcher. See Sign-in rules to require single sign-on or to let new members join automatically.
Troubleshooting
| What you see | What to check |
|---|---|
| Google shows 403 app_not_configured_for_user | The app is not turned on for that user’s organizational unit yet, or the change has not applied yet. |
| “The identity provider response was rejected: Invalid audience” | The Entity ID in Google differs from the one on the FormCan page. |
| “The identity provider response was rejected: Signature validation failed” | Google has a new certificate. Download the metadata again and paste the new certificate below the old one. |
| “The identity provider sent an email at @example.com, which is not one of your verified domains.” | The account’s primary email is on a domain you have not verified. |