> ## Documentation Index
> Fetch the complete documentation index at: https://macstadiuminc-add-bazel-rbe-integration-di574.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable SAML SSO with Google Workspace Federation

> Configure SAML SSO for MacStadium Portal via Google Workspace. Create a custom SAML app in Google Admin, download metadata, and send it to MacStadium.

<Note>SAML SSO is a paid offering. Contact your account team through the [Customer Portal](https://portal.macstadium.com) for more information.</Note>

<Warning>MacStadium does not support IdP-initiated logins. After SSO is configured, all users must log in at [portal.macstadium.com/sso](https://portal.macstadium.com/sso) using the ID provided by the MacStadium team.</Warning>

1. Go to [Google Admin Console](https://admin.google.com/)

2. Navigate to “Web and mobile apps” (Apps → Web and mobile apps in the left menu or use [this link](https://admin.google.com/ac/apps/unified))\\
   <img src="https://mintcdn.com/macstadiuminc-add-bazel-rbe-integration-di574/s6YP2z0Sg2ywf40O/images/attachments/28262749454747.png?fit=max&auto=format&n=s6YP2z0Sg2ywf40O&q=85&s=b9252d58ef7d8bc8c79c0e024edb2a45" alt="Google Admin Console left menu with Web and mobile apps option highlighted" width="2354" height="1466" data-path="images/attachments/28262749454747.png" />

3. Create a new “Custom SAML App” (click Add app)\\
   <img src="https://mintcdn.com/macstadiuminc-add-bazel-rbe-integration-di574/s6YP2z0Sg2ywf40O/images/attachments/28262749456027.png?fit=max&auto=format&n=s6YP2z0Sg2ywf40O&q=85&s=30188a3484a401c0cad1f4a5f7044112" alt="Google Admin Web and mobile apps page with Add app dropdown showing Custom SAML app" width="974" height="566" data-path="images/attachments/28262749456027.png" />

4. Enter “App name” (e.g. MacStadium Portal)

5. Download the metadata by clicking Download Metadata - Keep this file for sharing with our support team later.\\
   <img src="https://mintcdn.com/macstadiuminc-add-bazel-rbe-integration-di574/s6YP2z0Sg2ywf40O/images/attachments/28262763978523.png?fit=max&auto=format&n=s6YP2z0Sg2ywf40O&q=85&s=d430b31d8c4f1d7ad908829bf7748a6a" alt="Google SAML app setup with Download Metadata button" width="2560" height="1740" data-path="images/attachments/28262763978523.png" />

6. Configure
   * **ACS URL:** `https://idp.macstadium.com/saml2/idpresponse`
   * **Entity ID:** `urn:amazon:cognito:sp:us-east-1_pusi8jHs1`
   * Configure email mapping with the "Show Advanced Settings" menu
   * Select EMAIL for the Name ID Format field
   * Select Primary Email for the Name ID field\\
     <img src="https://mintcdn.com/macstadiuminc-add-bazel-rbe-integration-di574/s6YP2z0Sg2ywf40O/images/attachments/28262763979675.png?fit=max&auto=format&n=s6YP2z0Sg2ywf40O&q=85&s=3dd0f06b5f00afa70f1d0b5d45a7f70d" alt="Google SAML app Service Provider Details with ACS URL, Entity ID, and Name ID fields" width="2560" height="1740" data-path="images/attachments/28262763979675.png" />

7. Map Primary email to email\\
   <img src="https://mintcdn.com/macstadiuminc-add-bazel-rbe-integration-di574/s6YP2z0Sg2ywf40O/images/attachments/28262749462171.png?fit=max&auto=format&n=s6YP2z0Sg2ywf40O&q=85&s=a90c8b6babb529cb5941fd0deae80f74" alt="Google SAML app Attribute mapping with Primary Email mapped to email" width="2416" height="1642" data-path="images/attachments/28262749462171.png" />

8. Click Finish to complete the setup

9. Provide our support team with the metadata file from step 5
