Skip to main content
This guide walks through configuring SAML SSO with Google Workspace as your identity provider.
Email addresses in and Tuple must match exactly. For example, dev+tuple@company.com does not match dev@company.com. Verify your team’s email addresses before enabling SSO.
1

Add a custom SAML app

Sign in to your Google Workspace Admin console. Navigate to Apps > Web and mobile apps > Add app > Add custom SAML app.Navigate to add a custom SAML app
2

Create the app

Name the app “Tuple” and optionally upload an icon, which you can download here.App details
3

Configure your Tuple account

You are shown the Google Identity Provider details. Copy the values from this screen:Google Identity Provider detailsNavigate to the Settings tab of the team management dashboard.
Only team owners can access this page. To find out who your team owner is, check your profile.
Toggle Enable SAML to reveal the configuration form:SAML configuration form in TupleFill in the values with your metadata:Click Save Configuration to enable SAML for your team. Active sessions persist, but new logins are routed through . Log in at production.tuple.app/saml_check/new to verify the configuration.
4

Service provider details

Return to the Google Workspace Admin console and fill in the following fields:Service provider detailsACS URL
https://production.tuple.app/users/saml/auth
Entity ID
https://production.tuple.app/users/saml/metadata
5

Attribute mapping

Tuple requires two additional attributes: first_name and last_name.Attribute mappingAfter finishing the install wizard, click Test SAML Login to verify the configuration.Test SAML Login