Set up SSO with Google Workspace
Connect Google Workspace to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
Last updated 11 days ago
Part of Single sign-on (SSO) for your workspace: step 2 of 3, on Google Workspace.
Google Workspace speaks both protocols Tinct accepts. Choose OpenID Connect: it takes fewer steps, has no certificate to renew, and Tinct recognises each person by their Google account identifier, which does not change when their email address does. Choose SAML if your organisation manages all its applications as SAML apps in the Admin console.
You must be an admin of the workspace, and the workspace must be entitled to single sign-on. The screens below are those of the Google Cloud console and the Google Admin console as of 2026.
Before you start
- Verify at least one email domain: Verify your email domain. You can describe the connection first, but you cannot enable it until a domain is verified.
- Have a Google Workspace account on a verified domain to run the test sign-in with.
- For OpenID Connect: a Google Cloud project that belongs to your Workspace organisation, and the right to manage its OAuth clients.
- For SAML: a Google Workspace super admin account, the only role that can add SAML apps.
Option A: OpenID Connect
1. Set up the consent screen
- In the Google Cloud console, pick the project, then go to Google Auth Platform. If it has not been configured yet, click Get started.
- Under Branding, give an App name (
Tinct) and a User support email. - Under Audience, set the User type to Internal.
Internal limits the application to the accounts of your Workspace organisation: nobody else can even reach the consent screen, and Google asks for no app verification. It is only offered when the project belongs to your organisation.
The openid, email and profile scopes Tinct asks for are basic ones: nothing to add under Data access.
2. Create the client
- Under Clients, click Create client.
- Application type: Web application. Name:
Tinct. - Leave Authorized redirect URIs empty for now: Tinct gives you the redirect URI in step 4.
- Click Create, then copy the Client ID and the Client secret, or download the JSON file.
⚠️ Google shows the client secret only when it is created. If you lose it, add a new secret to the client and paste that one into Tinct.
3. Describe Google in Tinct
- In Tinct, go to Settings → Security, to the Identity provider card, and keep OpenID Connect.
- Fill in:
- Issuer:
https://accounts.google.com, exactly, with no/at the end - Client ID: the client ID from step 2, ending in
.apps.googleusercontent.com - Client secret: the secret from step 2
- Issuer:
- Click Save identity provider.
4. Register the redirect URI
- Copy the Redirect URI the card now shows.
- In the Google Cloud console, open the client, click Add URI under Authorized redirect URIs, paste it, and click Save.
Google warns that a change can take a few minutes to apply. If the test sign-in reports a redirect URI mismatch right away, wait a moment and try again.
Then go to Test, then enable.
Option B: SAML 2.0
1. Get Tinct's values
- In Tinct, go to Settings → Security, to the Identity provider card.
- Under Protocol, choose SAML 2.0. If no connection exists yet, click Get the values for my provider.
- Keep the card open: you need its Service provider entity ID and its Single sign-on URL (ACS).
2. Add a custom SAML app
- In the Google Admin console, go to Apps → Web and mobile apps, then Add app → Add custom SAML app.
- App name:
Tinct. Click Continue. - On Google Identity Provider details, click Download metadata (under Option 1). Keep the file: it is what you give Tinct in step 4. Click Continue.
- On Service provider details, fill in:
- ACS URL: Tinct's Single sign-on URL (ACS)
- Entity ID: Tinct's Service provider entity ID, pasted as is
- Start URL: leave it empty
- Signed response: leave it off. Google then signs the assertion, which Tinct accepts.
- Name ID format: EMAIL. Name ID: Basic Information > Primary email.
- Click Continue.
⚠️ Google has no identifier for a person that it can send as a persistent NameID: the primary email address is the usual choice. Tinct recognises a person by the NameID, so when someone's primary address changes in Google Workspace, Tinct no longer recognises their account. OpenID Connect does not have this limit.
3. Send the email and the names
On Attribute mapping, click Add mapping three times:
Click Finish.
4. Describe Google in Tinct
- Back in Tinct, under Values from your identity provider, choose Metadata document, and give the file you downloaded in step 2. Google publishes no metadata address: Tinct reads the file once and keeps Google's entity ID, sign-on URL and signing certificate.
- Click Save identity provider.
Leave Attribute names empty: email, firstName and lastName are among the names Tinct looks for.
5. Turn the app on for your people
A new SAML app is off for everyone. In the Admin console, open the Tinct app, click User access, choose On for everyone (or turn it on for the organisational units or groups that use Tinct), and click Save. Google says a change can take up to 24 hours to apply; it usually takes a few minutes.
Test, then enable
- In the Status card, click Test sign-in. A pop-up opens on Google's sign-in page.
- Sign in with a Workspace account whose address is on one of your verified domains.
- The result page shows the email address and the names Tinct received.
- Back on the Security page, click Enable.
With SAML, only the people the app is turned on for can sign in. With OpenID Connect, every account of your Workspace organisation can. Either way, Tinct only lets in addresses on your verified domains, and, when Create accounts at first sign-in is off, only people you invited.
When you are confident, go on to Require SSO in your workspace.
If something goes wrong
- Google shows Error 400: redirect_uri_mismatch (OpenID Connect). Authorized redirect URIs does not hold Tinct's Redirect URI exactly, or the change has not applied yet.
- Google shows Error 403: org_internal (OpenID Connect). The account is not in your Workspace organisation: the consent screen is Internal. Sign in with a Workspace account.
- Google shows app_not_configured_for_user (SAML). The app is not on for this person (step 5), or the change has not applied yet.
- Google shows app_not_configured (SAML). The Entity ID in Google is not exactly Tinct's Service provider entity ID.
- Tinct says the issuer could not be used. The issuer must be
https://accounts.google.com, with no/at the end. - Tinct says no email address was sent (SAML). The
emailmapping is missing (step 3). - Tinct says the address is not on a verified domain. The account's primary address is on another domain, a secondary domain of your Workspace for example: verify that domain too, or test with another account.
When Google's certificate expires
- OpenID Connect: nothing to do. Tinct reads Google's current keys from Google.
- SAML: Google's SAML certificate is valid for five years. Tinct emails your admins 30, 14, 7 and 1 day before it expires. In the Admin console, open the Tinct app, add a new certificate, download it, and register it in Tinct's Signing certificates card as the second certificate. Then switch the app to the new certificate in Google, and remove the old one from Tinct: see Rotate without downtime.