Google Workspace (SAML)
Use Hanzo IAM as SAML IdP for Google Workspace SSO.
This guide configures Hanzo IAM as a SAML identity provider for Google Workspace single sign-on.
Add a certificate in Hanzo IAM
Create an X.509 certificate with RSA in Hanzo IAM and download it.

Configure the SAML application in Hanzo IAM
- On the application edit page, select the certificate and add your Google domain (e.g.
google.com) to Redirect URLs. - Set SAML reply URL to
https://www.google.com/a/<your-domain>/acs. See SSO assertion requirements for the ACS URL. - Copy the Sign-in page URL for the next step.

Add third-party SAML IdP in Google Workspace
- In Google Workspace Admin → Security → Overview, find SSO with third-party IdP.
- Click Add SSO profile and enable Set up SSO with third-party identity provider.
- Paste the Hanzo IAM sign-in page URL into Sign-in page URL and Sign-out page URL.
- Upload the certificate you downloaded from Hanzo IAM and save.

Test with a user
- In Google Workspace, create a user (e.g. username
test). - In Hanzo IAM, create a user with the same username in the correct organization and set their email.

Sign-in flow: open the Google app (e.g. google.com) → sign in with the user’s email → redirect to Hanzo IAM → enter Hanzo IAM credentials → redirect back to Google when successful.

How is this guide?
Last updated on