> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.toggl.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Setting up SSO for Google Workspace

If you are setting up SSO for Google Workspace, these instructions will be useful for you!

1. In the Google Workspace Admin select **Apps:**
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-1-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-1-1.jpg)
2. Choose **Overview** and the **Web and Mobile Apps** tile:
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-2-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-2-1.jpg)
3. Click on the **Add app** dropdown and select **Add custom SAML app:**
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-3-1.png)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-3-1.png)
4. Give the app a name, a description and a logo. Your users will see those details on the list of apps available in the Google Workspace. Click **Continue**:
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-4-1.png)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-4-1.png)
5. You will be presented with **SSO URL**, **Entity ID** and a **Certificate.** We will need these values shortly.
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-5-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-5-1.jpg)
6. In a new browser window, go to Toggl Profile Settings and click on “Create SSO profile”. Set the profile name and the company domain:
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-6a-3.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-6a-3.jpg)

   *Note down the ACS URL and the Entity ID - we will use them shortly.*
7. Scroll down and fill the form with data obtained earlier from Google Workspace:
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-9-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-9-1.jpg)
8. Then click on **Submit for Review.**
9. Now go back to Google Workspace and fill in the values obtained from Toggl. Make sure to tick **Signed response**, select **EMAIL** as **Name ID Format** and use **Basic Information → Primary email** as the **Name ID.** Click **Continue**.

   **Note**: if you need your users to begin the SSO flow from your side (also known as Identity Provider initiated login) instead of doing so at [`https://accounts.toggl.com/track/sso-login/`](https://accounts.toggl.com/track/sso-login/) you should append `?toggl_product=track` at the end of the "ACS URL" field.

   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-7a-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-7a-1.jpg)
10. On the next screen simply click **Finish** as we do not require any additional attribute mapping:

    [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-8-1.png)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-8-1.png)
11. Make sure to assign users to the newly configured Toggl app or enable the app for all users:

    [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-10-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-10-1.jpg)![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-11-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-11-1.jpg)
12. At this point you are done with the configuration.   
       
    Please allow some time for the Toggl Support team to verify the configuration and that you are eligible to use the selected domain.   
       
    Once the verification process gets completed, you will be notified by email.