Skip to main content

Set Up SSO with Google Workspace

Step-by-step guide to configure SAML SSO between Google Workspace and your Tomba workspace.

Written by Tomba.io Team

Set Up SSO with Google Workspace

This guide shows you how to connect Google Workspace as your identity provider so your team can sign in to Tomba with their Google accounts.

Before you begin, make sure you have:

  • A Tomba Enterprise plan

  • Owner or Admin access to your Tomba workspace

  • Super Admin access to your Google Workspace


Step 1: Start in Google Admin

  1. Navigate to Apps > Web and mobile apps.

  2. Click Add app > Add custom SAML app.

[Image: google_add_saml_app.png] — Upload this image

  1. Enter an app name — for example, "Tomba".

  2. Optionally, upload the Tomba logo.

  3. Click Continue.


Step 2: Download Google IdP Metadata

  1. On the Google Identity Provider details screen, click Download Metadata.

[Image: google_download_metadata.png] — Upload this image

  1. Save the XML file to your computer — you'll upload it to Tomba later.

  2. Click Continue.


Step 3: Enter Tomba's Service Provider Details

  1. In a new browser tab, go to Settings > Workspace > SAML SSO in Tomba.

  2. From the Service Provider Details card, copy:

    • Entity ID (also called SAML Issuer)

    • ACS URL (Assertion Consumer Service URL)

  3. Back in Google Admin, fill in:

    • ACS URL — Paste the ACS URL from Tomba

    • Entity ID — Paste the Entity ID from Tomba

    • Name ID format — Select EMAIL

    • Name ID — Select Basic Information > Primary email

[Image: google_sp_details.png] — Upload this image

  1. Click Continue, then Finish.


Step 4: Upload Metadata to Tomba

  1. In Tomba, click Configure SAML SSO (or Update Metadata if reconfiguring).

  2. Choose Upload File and select the Google metadata XML you downloaded in Step 2.

  3. Tomba will show a preview of the parsed metadata. Verify the Entity ID and SSO URL look correct.

  4. Click Save Configuration.


Step 5: Turn On the App for Your Users

By default, the new SAML app is off for everyone in Google Workspace. You need to turn it on:

  1. In Google Admin, go to Apps > Web and mobile apps > Tomba.

  2. Click User access.

  3. Select ON for everyone (or choose specific organizational units).

  4. Click Save.

[Image: google_turn_on_app.png] — Upload this image

Note: Changes in Google Workspace can take up to 24 hours to take effect for all users, though it's usually much faster.


Step 6: Test the Connection

  1. Open an incognito/private browser window.

  2. Sign in using your Google account.

  3. You should land on the Tomba dashboard.


💡 Troubleshooting

"Authentication Failed" error?

  • Make sure the app is turned ON for your user in Google Admin.

  • Verify the Entity ID and ACS URL match exactly between Google and Tomba.

  • Check that Name ID is set to Primary email.

Certificate rotation

Google Workspace uses multiple signing certificates and rotates them periodically. Tomba automatically supports multiple certificates, so no action is needed on your part when Google rotates its keys. If you see certificate-related errors, try re-uploading the metadata from Google — it will include the latest certificates.


Related Resources

Need Help?

Got questions? Contact our support team — we're here to help!

Did this answer your question?