Google Workspace

This guide sets up SAML single sign-on from Google Workspace. You’ll need a
Google Workspace super administrator and a Twelfth workspace owner or admin.
Read Single sign-on & SCIM first if you haven’t.

Google sign-in vs. Google Workspace SSO

Twelfth already offers Continue with Google on the login page. Setting up
Workspace SSO adds what that can’t: your Workspace context-aware access, device
and session policies apply, and sign-in goes through your admin-controlled SAML
app rather than a per-person Google consent.

1. Create the custom SAML app

  1. In the Google Admin console, open Apps → Web
    and mobile apps → Add app → Add custom SAML app
    .
  2. Name it Twelfth and continue.
  3. On Google Identity Provider details, either Download metadata (the
    XML file) or copy the SSO URL, Entity ID and Certificate. Keep
    this tab open; you’ll need the metadata in step 3.

2. Paste Twelfth’s details into Google

In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on. Under Create the
app in your identity provider
you’ll find the values below with copy buttons.
On Google’s Service provider details page, set:

Google field Twelfth value
ACS URL Reply URL (Assertion Consumer Service) from the panel
Entity ID Identifier (Entity ID) from the panel
Start URL https://twelfth.ai/login (optional)
Name ID format EMAIL
Name ID Basic Information → Primary email

Continue to Attribute mapping and add these three, using exactly these app
attribute names:

Google directory attribute App attribute
Basic Information → First name firstName
Basic Information → Last name lastName
Basic Information → Primary email email

Finish.

3. Paste Google’s details into Twelfth

  1. In Twelfth’s panel, choose SAML 2.0 and enter your email domain (for
    example example.com).
  2. Paste the contents of the metadata XML you downloaded into …or paste the
    metadata XML
    (Google doesn’t publish a metadata URL for custom apps), and
    press Register identity provider.

4. Prove you own the domain

The panel shows a DNS TXT record. Add it at your DNS host — for a Workspace
domain that’s usually where your MX records already live — then press Check
now
. Sign-in through Google Workspace SSO is refused until it resolves.

5. Turn the app on and test

  1. In the Admin console, open the Twelfth app, then User access, and turn it
    ON for everyone (or for the organisational units that should have it).
    Google can take a few minutes to apply.
  2. Sign out of Twelfth, open the login page, choose
    See other login methods → Continue with single sign-on, and enter your
    work email.

Provisioning

Google Workspace only auto-provisions to apps in its pre-integrated catalogue,
so SCIM from Google Workspace is not available for Twelfth. Manage
membership through Members — invitations for joiners,
deactivation for leavers — or provision from a directory that supports SCIM to
custom apps (Entra ID, Okta).

Troubleshooting

  • Google error “app_not_configured_for_user” — the app isn’t turned on for
    that person’s organisational unit (step 5).
  • “Provider domain has not been verified” — the DNS record hasn’t resolved
    yet.
  • Signed in with no display name — the attribute mapping in step 2 wasn’t
    saved with the exact names firstName, lastName, email.