Skip to main content
Connect OpenCX to Google Workspace with a custom SAML app from the Google Admin console. Google Workspace does not offer SCIM to third parties, so provisioning is just-in-time: members are created on first login.

Before you start

1

Confirm your admin role

You need a Super Admin account in the Google Admin console.
2

Have your OpenCX SP details ready

1. Create the custom SAML app

1

Open the SAML apps list

In the Google Admin console go to Apps → Web and mobile apps → Add app → Add custom SAML app.
2

Name the app

Set the name to OpenCX, optionally add the logo, and click Continue.
3

Copy Google's IdP details

On the Google Identity Provider details step, download the Metadata (or copy the SSO URL, Entity ID, and Certificate). You’ll hand this to OpenCX. Click Continue.
4

Enter the OpenCX service provider details

  • ACS URL → your OpenCX ACS URL
  • Entity ID → your OpenCX SP Entity ID
  • Name ID formatEMAIL
  • Name IDBasic Information > Primary email
Click Continue.

2. Map attributes

On the Attribute mapping step, add:
Google Workspace can send group membership as a claim: add a group mapping, pick the groups OpenCX should know about, and map them to an app attribute named groups. Use this for role mapping. If you skip it, everyone lands as the default role.
Click Finish.

3. Hand your metadata to OpenCX

Give the metadata you downloaded in step 1 (or the SSO URL, Entity ID, and certificate) to your OpenCX contact. We register your Google issuer, SSO endpoint, and signing certificate on your connection.

4. Turn on access

1

Set the service to ON

Open the app → User access. Google apps default to OFF. Turn it ON for everyone, or ON only for the organizational units / groups that should reach OpenCX.
2

Wait for propagation

Google access changes can take a few minutes (occasionally up to 24 hours) to propagate. Give it time before testing.

5. Test the login

1

IdP-initiated

From a pilot user’s Google account, open the apps grid (waffle) → OpenCX, or https://myapps.google.com, and click the OpenCX tile.
2

SP-initiated

In a private window, go to platform.open.cx, enter the pilot’s work email, and confirm the redirect to Google and back to the OpenCX Inbox.
3

Confirm the role

Verify the expected OpenCX role landed. If not, check the group mapping and your role mapping.

6. Enforce

When the pilot is clean, ask OpenCX to enforce SSO for your domain. Read the pre-cutover checklist first and secure your break-glass account.

Troubleshooting

More in Troubleshooting SSO.