Set up SSO with Google Workspace
Create a custom SAML app in Google Workspace and connect it to Spaceboy.
Before you start
You'll need Google Workspace super-admin access and an Enterprise organization on Spaceboy with a verified email domain (step 1 on the SSO settings page). Spaceboy's SAML service-provider details, used below, are:
ACS URL
https://ajnqjufvbyhobolsxyyo.supabase.co/auth/v1/sso/saml/acs
Entity ID
https://ajnqjufvbyhobolsxyyo.supabase.co/auth/v1/sso/saml/metadata
Google Workspace provides its IdP metadata as a downloadable XML file rather than a hosted URL — you'll paste the XML into Spaceboy in the last step.
1. Create the custom SAML app
- In the Google Admin console, go to Apps → Web and mobile apps, and choose Add app → Add custom SAML app.
- Name the app (for example, "Spaceboy") and continue.
- On the Google Identity Provider details step, choose Download metadata and keep the XML file — Spaceboy needs it. Continue.
- On the Service provider details step, set ACS URL and Entity ID to the values above, leave Signed response unchecked, and set Name ID format to EMAIL with Name ID as Basic Information → Primary email.
- Finish the wizard — no attribute mapping is required.
2. Turn the app on for your users
New SAML apps are off by default. On the app's page, open User access and turn it ON for everyone or for the organizational units that should reach Spaceboy. Google may take a few minutes to apply the change.
3. Connect Google Workspace to Spaceboy
- In Spaceboy, open Organization settings → Single Sign-On and choose Metadata XML.
- Paste the contents of the metadata file you downloaded from Google and select Connect provider.
- Test it: from Spaceboy's sign-in page, choose Continue with SSO and enter your work email. You should be redirected to Google and back into Spaceboy.
Once sign-in works for a test account, consider turning on Enforce SSO so members on your verified domains must use Google.
Enforcing SSO