SSO with Google Workspace
Step by step — create a custom SAML app, download the metadata file, set the Name ID to EMAIL.
This is how you connect a workspace to Google Workspace. The overall order (verify the domain first, then the connection) is described under Enterprise sign-in; this page fills in the part that happens in the Google Admin console.
One peculiarity up front: Google provides no metadata URL, only a file to download. In verstag you therefore use the "XML file" source — and after a certificate rotation at Google you upload a new file, because nothing can be re-fetched from a file.
The menu paths match the Google Admin console as of September 2026.
What you need
- In verstag: a verified e-mail domain and the „Unternehmens-Anmeldung (SSO)“ (Enterprise sign-in) card under Settings → „Sicherheit & SSO“. Under „Werte für den Identitätsanbieter“ (Values for the identity provider) it shows the two values, with copy buttons, that you are about to enter.
- In Google: an account with super-admin rights for the Admin console.
Step 1: Create a custom SAML app
- Open the Google Admin console and go to Menu → Apps → Web and mobile apps.
- Choose Add app → Add custom SAML app.
- Enter a name (say, "verstag") and continue.
Step 2: Download the metadata file
On the "Google Identity Provider details" page, choose "DOWNLOAD
METADATA". The file is called GoogleIDPMetadata.xml — it is what verstag is
about to receive. You do not need the SSO URL and certificate shown beside it
individually; they are inside the file.
Step 3: Enter the service provider details
On the "Service provider details" page, enter the two values from the verstag card:
- ACS URL → the value „ACS-URL (Reply URL)“
- Entity ID → the value „Entity ID (Identifier)“
Then the one setting a Google connection otherwise fails on:
- Name ID format: EMAIL
- Name ID: Basic Information → Primary email
verstag matches a sign-in by e-mail address. If the Name ID is not the primary e-mail address, the sign-in carries no address and is refused — even when everything else is right.
You do not need an additional attribute mapping.
Step 4: Turn the app on for users
After creation the app stands at "OFF for everyone". Open User access in the app's overview and switch it ON — for everyone, or for the organisational units that should use verstag. Google usually needs a few minutes before the change applies everywhere — occasionally considerably longer.
Step 5: Upload it in verstag
Back on the „Unternehmens-Anmeldung (SSO)“ card:
- Set the source to „XML-Datei“ (XML file) and pick the downloaded
GoogleIDPMetadata.xml. - Pick the role for new members and decide about automatic admission.
- „Verbindung speichern“ (Save connection).
Check it
Sign in through your workspace's sign-in address (the page's third card). Use that route instead of the test button in the Google console too: the button starts the sign-in at Google, the sign-in address starts it at verstag — and that is the route your members take.
When Google rotates the certificate
Google certificates expire after a few years; the Admin console shows this under Security → Authentication → SSO with SAML applications. Download the new metadata file then and upload it in verstag again — an uploaded file does not refresh itself.