Skip to content

Set up SSO with Google Workspace

Add a custom SAML app in the Google Admin console so your Workspace users sign in to Infinite Audience. You need a Google Workspace super admin and an owner/admin role in Infinite Audience with the Enterprise tier.

  1. In the Google Admin console (admin.google.com), go to Apps → Web and mobile apps.
  2. Click Add app → Add custom SAML app.
  3. Give the app a name (e.g. “Infinite Audience”) and click Continue.

On the Google Identity Provider details screen, collect these before moving on:

  1. Copy the SSO URL → this is our IdP SSO URL.
  2. Copy the Entity ID → this is our IdP Entity ID.
  3. Click Download certificate → this is the signing certificate (a PEM -----BEGIN CERTIFICATE----- file). Click Continue.

3. Paste our SP values (Service Provider details)

Section titled “3. Paste our SP values (Service Provider details)”

On the Service Provider details screen, enter the values from your Infinite Audience Connection Setup card:

  1. ACS URL → paste our ACS URL. It looks like https://<app-domain>/__/auth/handler.
  2. Entity ID → paste our SP Entity ID. It looks like https://<app-domain>/saml/<your-slug>.
  3. Name ID formatEMAIL. Name IDBasic Information > Primary email. Click Continue.
  1. On the Attribute mapping screen you can click Finish (no extra attributes are required — the email NameID is enough).
  2. Open the app and set User access to ON for the organizational units or groups who should sign in. It can take a few minutes to take effect.

5. Complete the connection in Infinite Audience

Section titled “5. Complete the connection in Infinite Audience”
  1. In the Connection Setup card, paste the IdP Entity ID, IdP SSO URL, and the certificate PEM, then save.
  2. Claim and verify your email domain — see the DNS verification guide.
  3. Run Test Connection, confirm the NameID is your email, then Activate.

Users sign in at our sign-in page by entering their work email — not from the Google apps launcher tile (IdP-initiated sign-in is not supported). If a sign-in fails, see the troubleshooting guide.