Google Workspace
This guide sets up SAML single sign-on from Google Workspace. You’ll need a
Google Workspace super administrator and a Twelfth workspace owner or admin.
Read Single sign-on & SCIM first if you haven’t.
Twelfth already offers Continue with Google on the login page. Setting up
Workspace SSO adds what that can’t: your Workspace context-aware access, device
and session policies apply, and sign-in goes through your admin-controlled SAML
app rather than a per-person Google consent.
1. Create the custom SAML app
- In the Google Admin console, open Apps → Web
and mobile apps → Add app → Add custom SAML app. - Name it Twelfth and continue.
- On Google Identity Provider details, either Download metadata (the
XML file) or copy the SSO URL, Entity ID and Certificate. Keep
this tab open; you’ll need the metadata in step 3.
2. Paste Twelfth’s details into Google
In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on. Under Create the
app in your identity provider you’ll find the values below with copy buttons.
On Google’s Service provider details page, set:
| Google field | Twelfth value |
|---|---|
| ACS URL | Reply URL (Assertion Consumer Service) from the panel |
| Entity ID | Identifier (Entity ID) from the panel |
| Start URL | https://twelfth.ai/login (optional) |
| Name ID format | |
| Name ID | Basic Information → Primary email |
Continue to Attribute mapping and add these three, using exactly these app
attribute names:
| Google directory attribute | App attribute |
|---|---|
| Basic Information → First name | firstName |
| Basic Information → Last name | lastName |
| Basic Information → Primary email | email |
Finish.
3. Paste Google’s details into Twelfth
- In Twelfth’s panel, choose SAML 2.0 and enter your email domain (for
exampleexample.com). - Paste the contents of the metadata XML you downloaded into …or paste the
metadata XML (Google doesn’t publish a metadata URL for custom apps), and
press Register identity provider.
4. Prove you own the domain
The panel shows a DNS TXT record. Add it at your DNS host — for a Workspace
domain that’s usually where your MX records already live — then press Check
now. Sign-in through Google Workspace SSO is refused until it resolves.
5. Turn the app on and test
- In the Admin console, open the Twelfth app, then User access, and turn it
ON for everyone (or for the organisational units that should have it).
Google can take a few minutes to apply. - Sign out of Twelfth, open the login page, choose
See other login methods → Continue with single sign-on, and enter your
work email.
Provisioning
Google Workspace only auto-provisions to apps in its pre-integrated catalogue,
so SCIM from Google Workspace is not available for Twelfth. Manage
membership through Members — invitations for joiners,
deactivation for leavers — or provision from a directory that supports SCIM to
custom apps (Entra ID, Okta).
Troubleshooting
- Google error “app_not_configured_for_user” — the app isn’t turned on for
that person’s organisational unit (step 5). - “Provider domain has not been verified” — the DNS record hasn’t resolved
yet. - Signed in with no display name — the attribute mapping in step 2 wasn’t
saved with the exact namesfirstName,lastName,email.