Before you start
1
Confirm your admin role
You need a Super Admin account in the Google Admin console.
2
Have your OpenCX SP details ready
1. Create the custom SAML app
1
Open the SAML apps list
In the Google Admin console go to Apps → Web and mobile apps → Add app → Add custom SAML app.
2
Name the app
Set the name to
OpenCX, optionally add the logo, and click Continue.3
Copy Google's IdP details
On the Google Identity Provider details step, download the Metadata (or copy the SSO URL, Entity ID, and Certificate). You’ll hand this to OpenCX. Click Continue.
4
Enter the OpenCX service provider details
- ACS URL → your OpenCX ACS URL
- Entity ID → your OpenCX SP Entity ID
- Name ID format → EMAIL
- Name ID → Basic Information > Primary email
2. Map attributes
On the Attribute mapping step, add:Google Workspace can send group membership as a claim: add a group mapping, pick the groups OpenCX should know about, and map them to an app attribute named
groups. Use this for role mapping. If you skip it, everyone lands as the default role.3. Hand your metadata to OpenCX
Give the metadata you downloaded in step 1 (or the SSO URL, Entity ID, and certificate) to your OpenCX contact. We register your Google issuer, SSO endpoint, and signing certificate on your connection.4. Turn on access
1
Set the service to ON
Open the app → User access. Google apps default to OFF. Turn it ON for everyone, or ON only for the organizational units / groups that should reach OpenCX.
2
Wait for propagation
Google access changes can take a few minutes (occasionally up to 24 hours) to propagate. Give it time before testing.
5. Test the login
1
IdP-initiated
From a pilot user’s Google account, open the apps grid (waffle) → OpenCX, or
https://myapps.google.com, and click the OpenCX tile.2
SP-initiated
In a private window, go to platform.open.cx, enter the pilot’s work email, and confirm the redirect to Google and back to the OpenCX Inbox.
3
Confirm the role
Verify the expected OpenCX role landed. If not, check the group mapping and your role mapping.
6. Enforce
When the pilot is clean, ask OpenCX to enforce SSO for your domain. Read the pre-cutover checklist first and secure your break-glass account.Troubleshooting
More in Troubleshooting SSO.