Configure SSO with Google Workspace

Before you begin — Read SSO Integration: How It Works first. Each user's Sfax Username must equal their Google primary email.

In the Google Admin console, go to Apps › Web and mobile apps › Add custom SAML app, then complete the Service Provider Details.

Google field Value
ACS URL https://app.sfaxme.com/sso/sso.aspx
Entity ID https://app.sfaxme.com/
Start URL Leave blank (Start URL sets RelayState)
Name ID format EMAIL
Name ID Basic Information › Primary email (the default)
Signed response Leave unchecked. Sfax requires the assertion to be signed, which Google does by default; signing the full response is not required.

Then turn the app ON for the correct organizational unit or access group.

Leave Start URL blank — Google's Start URL sets the SAML RelayState. Pointing it at a Sfax URL can force a redirect that blocks sign-in, so leave it empty and launch Sfax from the Google app launcher.

‹ Back to SSO overview