Set Up SSO with Google Workspace
This guide shows you how to connect Google Workspace as your identity provider so your team can sign in to Tomba with their Google accounts.
Before you begin, make sure you have:
A Tomba Enterprise plan
Owner or Admin access to your Tomba workspace
Super Admin access to your Google Workspace
Step 1: Start in Google Admin
Go to admin.google.com.
Navigate to Apps > Web and mobile apps.
Click Add app > Add custom SAML app.
[Image: google_add_saml_app.png] — Upload this image
Enter an app name — for example, "Tomba".
Optionally, upload the Tomba logo.
Click Continue.
Step 2: Download Google IdP Metadata
On the Google Identity Provider details screen, click Download Metadata.
[Image: google_download_metadata.png] — Upload this image
Save the XML file to your computer — you'll upload it to Tomba later.
Click Continue.
Step 3: Enter Tomba's Service Provider Details
In a new browser tab, go to Settings > Workspace > SAML SSO in Tomba.
From the Service Provider Details card, copy:
Entity ID (also called SAML Issuer)
ACS URL (Assertion Consumer Service URL)
Back in Google Admin, fill in:
ACS URL — Paste the ACS URL from Tomba
Entity ID — Paste the Entity ID from Tomba
Name ID format — Select EMAIL
Name ID — Select Basic Information > Primary email
[Image: google_sp_details.png] — Upload this image
Click Continue, then Finish.
Step 4: Upload Metadata to Tomba
In Tomba, click Configure SAML SSO (or Update Metadata if reconfiguring).
Choose Upload File and select the Google metadata XML you downloaded in Step 2.
Tomba will show a preview of the parsed metadata. Verify the Entity ID and SSO URL look correct.
Click Save Configuration.
Step 5: Turn On the App for Your Users
By default, the new SAML app is off for everyone in Google Workspace. You need to turn it on:
In Google Admin, go to Apps > Web and mobile apps > Tomba.
Click User access.
Select ON for everyone (or choose specific organizational units).
Click Save.
[Image: google_turn_on_app.png] — Upload this image
Note: Changes in Google Workspace can take up to 24 hours to take effect for all users, though it's usually much faster.
Step 6: Test the Connection
Open an incognito/private browser window.
Go to app.tomba.io/auth/signin.
Sign in using your Google account.
You should land on the Tomba dashboard.
💡 Troubleshooting
"Authentication Failed" error?
Make sure the app is turned ON for your user in Google Admin.
Verify the Entity ID and ACS URL match exactly between Google and Tomba.
Check that Name ID is set to Primary email.
Certificate rotation
Google Workspace uses multiple signing certificates and rotates them periodically. Tomba automatically supports multiple certificates, so no action is needed on your part when Google rotates its keys. If you see certificate-related errors, try re-uploading the metadata from Google — it will include the latest certificates.
Related Resources
SAML Single Sign-On (SSO) — SSO overview
Set Up SAML SSO — General setup guide for all identity providers
SSO Enforcement Modes — Control how your team signs in
Verify Your Domain for SSO — Enable SSO login discovery
Need Help?
Got questions? Contact our support team — we're here to help!
