## Create SAML application with Google This guide outlines the steps to create and configure a SAML application in Google, including setup, user assignments, and metadata submission. ### Step 1: Create SAML application 1. Log in to your Google Workspace dashboard and click **Web and mobile apps** in the sidebar. ![google](/assets/google-1.605f4fb7a0c2134bf1f5dd63505599ca6b5dada6c6d10a6568ccaf047021dbaa.dba07de7.png) 1. Choose **Add custom SAML app**. ![google](/assets/google-2.29d2468d6579b2ce714de117028f949d877b63154dec17c865e8d102fe0ef561.dba07de7.png) 1. Enter the name of your application, then click **Continue**. ![google](/assets/google-3.cb208e73cf6d9dfba30a2a9821f3baf8c7fa586478417e62bbcb05f00a28d422.dba07de7.png) 1. Skip to the next screen by clicking **Continue**. ![google](/assets/google-4.d6ce4aa833830dafafe2f56dbf9e3e5ce89774f39a8a1810bf3547f686e7d8ed.dba07de7.png) 1. Copy and paste the values into the relevant fields in the **Service provider details** section. ![google](/assets/google-5.9272286685be93137a94dfffaf0a1270bdc63ddf82f08151a1bbec989b45e1f1.dba07de7.png) 1. Paste the **ACS URL** and **Entity ID** in the relevant fields. ![google](/assets/google-6.2fa981b966459239bb4f6ecf0f4199dbbcb31d38c295e9bea8535141d5a426dd.dba07de7.png) ### Step 2: Fill attribute statements (optional) 1. Go to **Attribute mapping (optional)** in SAML Settings, fill in the following Attribute Statements: ![google](/assets/google-7.12a8482a61cf1e27c0a559fef5513029c117944fa63804d504949140a69a60a5.dba07de7.png) 1. Fill in the following Attribute Statements and click **Finish**: ![google](/assets/google-8.7019f881b0632faeb5585bfe1d87431f4d94c8c3cf3373eaf49d9357e65a1f9d.dba07de7.png) ### Step 3: Assign users 1. Enable user access to the SAML application and click **Save**. ![google](/assets/google-9.07cd858b8129bacd77059e2c1bab3bc82a490c7f80ec53a9ce0134320d2b936e.dba07de7.png) ![google](/assets/google-10.05f8f3f9409825b1b75cf66e238800ec13ebe73fdb9842921ab157a64e383eaa.dba07de7.png) ### Step 4: Submit metadata To complete the implementation of SAML SSO, you need to provide the application with your identity provider’s details. 1. Click on the **Download metadata**. ![google](/assets/google-11.56b00cf5831d7744d029f8dc97a137ef9954d6e4418d98535a3d81b5f9cd9aca.dba07de7.png) #### Automatic configuration 1. Download the metadata file. ![google](/assets/google-12.fc4c5ac26a5bcd49ddf1e4c0362d10e1605caea4ccf66eed463203328376729f.dba07de7.png) 1. Upload the file from the previous step. #### Manual configuration 1. Copy the value of the **SSO URL** and **X.509 Certificate** fields. ![google](/assets/google-14.7933633a8ad34db6e0ed90f00522de07022502d2cf32fbc12d25473368cb7edb.dba07de7.png) 1. Paste below the copied values from the previous step. ![google](/assets/google-15.7adac461a6a201f676190b07b3af1b2d64a6330a769bc6e4d78a5ef8fa29af55.dba07de7.png) ### Step 5: Proceed with domain claiming and role assignment 1. Click on **Proceed with domain claiming and role assignment** to confirm the completion the configuration of the IDP form. 2. Follow the instructions in the [Self-service SAML configuration](/ciam/guides/authentication/sso/self-service/saml#claim-domain) guide to complete this step and manage authorization.