About this page
This page explains how to use Google Workspace as an IdP and set up SAML integration with ZUNDA ID. Once you complete this setup, users signed in to Google Workspace can use those credentials to log in to ZUNDA ID via single sign-on.
What you'll need
Make sure you have the following ready in advance.
-
A Google Workspace user with permission to manage apps
You need a Google account with admin permissions to create and configure a custom SAML app.
-
A ZUNDA ID user with authentication method admin permissions
You need a user with ZUNDA ID admin permissions to create and configure the SAML provider.
-
A recovery key issued and stored in advance
To prevent a lockout caused by a misconfiguration or an IdP outage, see How to Configure Recovery Settings for Login Methods and issue a recovery key in advance.
Setup steps
You'll switch back and forth between ZUNDA ID and Google Workspace. It's easiest to keep both open at the same time.
- Open the Login Method Settings screen in ZUNDA ID, and click Add SAML Provider.
In the dialog that appears, enter a display name of your choice to identify this provider (for example, Google Workspace), and click Create to go to the provider details screen. The name you enter here is shown on the login screen and in settings screens.
- Open the Google Workspace admin console, and add a custom SAML app from Web and Mobile Apps.
Log in to the Google Workspace admin console (admin.google.com), go to Apps → Web and Mobile Apps, and select Add Custom SAML App from Add App.
Enter a recognizable app name such as ZUNDA ID. This name is shown in the app list for Google Workspace users, so choose something users can easily identify. Optionally upload an icon, and click Continue to proceed through the wizard.
- When the Google Identity Provider details screen appears, download and save the IdP Metadata.
The IdP metadata is an XML file containing the information ZUNDA ID needs, such as the SSO URL, entity ID, and public key certificate. You'll import this file into ZUNDA ID in a later step, so save it somewhere you can easily access it temporarily.
- Click Next to open the Service Provider (SP) details screen, and enter the following parameters.
The values you configure here become the destination and identifiers Google Workspace uses when sending authentication responses to ZUNDA ID. Just follow the prompts on screen.
- ACS URL
https://id.zunda.co.jp/auth/saml/acs - Entity ID
https://id.zunda.co.jp/saml/sp - Name ID format
EMAIL - Name ID
Basic Information > Primary email
- Click Next to open the attribute mapping screen, and add the following attributes.
Here, you'll configure the mapping that sends the Google Workspace user's first and last name to ZUNDA ID. For Directory Attributes, select First Name and Last Name, and enter the following URLs for App Attributes.
- First Name
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname - Last Name
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
Once you've entered all the mappings, click Finish to close the setup wizard. The app is created, and the Google Workspace-side setup is complete for now.
- Return to the provider details screen in ZUNDA ID, click Import Metadata XML, and import the IdP metadata XML you downloaded from Google Workspace earlier.
Importing the IdP metadata sets up, in one step, the SSO URL, entity ID, IdP certificate, and other settings ZUNDA ID needs to verify responses from Google Workspace.
In the dialog that appears, click Upload from file and select the IdP metadata XML file you saved earlier.
Confirm the file has loaded, then click Import Metadata XML. If the file is invalid, an error is displayed — if that happens, download the IdP metadata from Google Workspace again and retry.
Confirm that the IdP Entity ID, SSO URL, IdP certificate, and other fields have all been imported. The SAML provider setup on the ZUNDA ID side is now complete. In the next step, you'll run a login test to confirm the settings work correctly.
Login test
Once the setup is complete, always run a login test before enabling the provider to confirm the settings are correct and that Google Workspace user information imports correctly.
- From the Google Workspace provider details screen in ZUNDA ID, click the Test button.
Clicking the Test button opens the Google login screen in a pop-up window. If pop-ups are blocked, temporarily disable your browser's pop-up blocker.
- Once you complete authentication with Google Workspace, "SSO login test succeeded" is displayed. The setup is complete once the check results for NameID, Email, Surname, and Given name all show green checkmarks.
If an error is displayed, or a check item is marked in red, check the following:
- Whether the IdP metadata XML was imported correctly
- Whether the attribute mapping (First Name / Last Name) is configured correctly on the Google Workspace side
- Whether the service provider details (ACS URL, entity ID) are correct on the Google Workspace side
Once the test succeeds, return to the provider details screen and switch Status to ON to enable SAML login via Google Workspace. After that, select this provider as a login method in Domain Settings so actual users can log in using SAML authentication.
We strongly recommend completing How to Configure Recovery Settings for Login Methods in advance, in case the login method becomes unavailable. Once your setup is complete, see How to Use the SAML Provider You Created as a Login Method to enable it as a login method.