SSO with Google Workspace

Step by step — create a custom SAML app, download the metadata file, set the Name ID to EMAIL.

This is how you connect a workspace to Google Workspace. The overall order (verify the domain first, then the connection) is described under Enterprise sign-in; this page fills in the part that happens in the Google Admin console.

One peculiarity up front: Google provides no metadata URL, only a file to download. In verstag you therefore use the "XML file" source — and after a certificate rotation at Google you upload a new file, because nothing can be re-fetched from a file.

The menu paths match the Google Admin console as of September 2026.

What you need

  • In verstag: a verified e-mail domain and the „Unternehmens-Anmeldung (SSO)“ (Enterprise sign-in) card under Settings → „Sicherheit & SSO“. Under „Werte für den Identitätsanbieter“ (Values for the identity provider) it shows the two values, with copy buttons, that you are about to enter.
  • In Google: an account with super-admin rights for the Admin console.

Step 1: Create a custom SAML app

  1. Open the Google Admin console and go to Menu → Apps → Web and mobile apps.
  2. Choose Add app → Add custom SAML app.
  3. Enter a name (say, "verstag") and continue.

Step 2: Download the metadata file

On the "Google Identity Provider details" page, choose "DOWNLOAD METADATA". The file is called GoogleIDPMetadata.xml — it is what verstag is about to receive. You do not need the SSO URL and certificate shown beside it individually; they are inside the file.

Step 3: Enter the service provider details

On the "Service provider details" page, enter the two values from the verstag card:

  • ACS URL → the value „ACS-URL (Reply URL)“
  • Entity ID → the value „Entity ID (Identifier)“

Then the one setting a Google connection otherwise fails on:

  • Name ID format: EMAIL
  • Name ID: Basic Information → Primary email

verstag matches a sign-in by e-mail address. If the Name ID is not the primary e-mail address, the sign-in carries no address and is refused — even when everything else is right.

You do not need an additional attribute mapping.

Step 4: Turn the app on for users

After creation the app stands at "OFF for everyone". Open User access in the app's overview and switch it ON — for everyone, or for the organisational units that should use verstag. Google usually needs a few minutes before the change applies everywhere — occasionally considerably longer.

Step 5: Upload it in verstag

Back on the „Unternehmens-Anmeldung (SSO)“ card:

  1. Set the source to „XML-Datei“ (XML file) and pick the downloaded GoogleIDPMetadata.xml.
  2. Pick the role for new members and decide about automatic admission.
  3. „Verbindung speichern“ (Save connection).

Check it

Sign in through your workspace's sign-in address (the page's third card). Use that route instead of the test button in the Google console too: the button starts the sign-in at Google, the sign-in address starts it at verstag — and that is the route your members take.

When Google rotates the certificate

Google certificates expire after a few years; the Admin console shows this under Security → Authentication → SSO with SAML applications. Download the new metadata file then and upload it in verstag again — an uploaded file does not refresh itself.