1. Help Center
  2. School
  3. 3rd Party Integrations

How do I set up Google Workspace SSO?

The following instructions are for creating a SAML-based SSO connection through Google Workspace. 

Set up your own custom SAML app

  1. Sign in to your Google Admin console, using an account with super administrator privileges.
  2. In the Admin console, go to Menu "" > Apps Web and mobile apps.
  3. Click Add App > Add custom SAML app.
  4. On the App Details page:
    1. Enter the name of the custom app.
    2. (Optional) Upload an app icon.
  5. Click Continue.
  6. On the Google Identity Provider details page, get the setup information needed by the service provider using one of these options:
    • Download the IDP metadata.
    • Copy the SSO URL and Entity ID and download the Certificate.
  7. In a separate browser tab or window, sign into Hook Security, Inc
  8. Navigate to one of the following:
    • For portal SSO: Administration > Settings > Account Settings > SSO tab .
    • For school SSO: AdministrationSettings > School Settings > SSO tab. 
  9. Enter the information you copied in Step 6 (SSO URL --> ACS Endpoint URL and Entity ID --> Issuer URL) into the Hook Security, Inc SSO configuration page:
    Google SSO IDP settings 1.png
  10. Open the downloaded Certificate in your preferred text editor and copy all the contents.
  11. Paste the Certificate contents into the 'x.509 Certificate' field under Identity Provider (IDP) Settings in Hook Security, Inc:
  12. Click "Save"
  13. Return to the Google Admin Console.
  14. Click "Continue".
  15. In the Service Provider Details window, enter the ACS URLEntity ID from the Hook Security, Inc portal.
    Google SSO SP details.png
  16. Set the Name ID format to email.
  17. The default Name ID is the primary email.
  18. Click "Continue".
  19. Click "Finish".

Turn on your SAML app

  1. Sign into your Google Admin console, using an account with super administrator privileges.
  2. In the Admin console, go to Menu "" > Apps > Web and mobile apps.
  3. Select your SAML app.
  4. Click "User access".
  5. To turn on or off a service for everyone in your organization, click On for everyone or Off for everyone, and then click "Save".

  6. (Optional) To turn a service on or off for an organizational unit:
    1. At the left, select the organizational unit.
    2. To change the Service status, select On or Off.
    3. Choose one:
      • If the Service status is set to Inherited and you want to keep the updated setting, even if the parent setting changes, click Override.
      • If the Service status is set to Overridden, either click Inherit to revert to the same setting as its parent, or click Save to keep the new setting, even if the parent setting changes.
  7. To turn on a service for a set of users across or within organizational units, select an access group. 
  8. Ensure that the email addresses your users use to sign in to the SAML app match the email addresses they use to sign in to your Google domain.
NOTE: Changes can take up to 24 hours but typically happen more quickly.

Using the App

Once the app is created and configured, the app will appear in 'Google apps'.


Custom apps will appear at the bottom of this list. The link address can be copied by right-clicking the app and selecting "Copy link address". You can place this link in the "App embed link" field (Administration > Settings > School Settings OR Account Settings > Portal SSO tab) so the {school_app_embed_link} and {portal_app_embed_link} variables can be used in system emails. Placing this link in system emails will allow students/admins to sign-in directly from the system email.