Skip to main content

Set up SAML SSO with Google Workspace

Connect DealRoom to Google Workspace so your team signs in to DealRoom with their Google accounts.

Connect DealRoom to Google Workspace so your team signs in to DealRoom with their Google accounts.

Before you start

  • You need to be a DealRoom organization admin and a Google Workspace super administrator.

  • Talk to your Customer Success Manager (CSM) first. See How do I set up SSO with DealRoom?

  • Keep two browser tabs open, one for DealRoom and one for the Google Admin console. You'll copy values between them.

Step 1: Start the integration in DealRoom

  1. In DealRoom, go to Settings → Authentication.

  2. In the SAML Integration section, click Create SAML Integration.

  3. DealRoom shows its SAML endpoints. You'll need these in Step 4:

    • Metadata (Entity ID/Metadata URL): https://<your-subdomain>.dealroom.net/saml/metadata

    • ACS (Assertion Consumer Service): https://<your-subdomain>.dealroom.net/saml/acs

Keep this tab open.

Step 2: Create a custom SAML app in Google Admin

  1. In a new tab, open the Google Admin console and go to Apps → Web and mobile apps.

  2. Click Add app → Add custom SAML app.

  3. On App details, enter a name, for example DealRoom, and click Continue.

Step 3: Copy Google's identity provider details into DealRoom

On the Google Identity Provider details page, copy each value into the DealRoom form:

Google field

DealRoom field

SSO URL

Single Sign On URL

Entity ID

Entity ID

Certificate

x509 public certificate (paste the whole certificate, including the BEGIN and END lines)

(Google doesn't provide one)

Single Log Out URL: enter https://accounts.google.com/o/saml2/doesNotSupport

Note: Google Workspace doesn't support SAML single logout. The URL above is a placeholder that fills the required field.

In DealRoom, the identity provider settings should now look like this:

Click Continue in Google Admin.

Step 4: Enter DealRoom's details in Google Admin

On the Service provider details page:

Google field

Value

ACS URL

DealRoom's ACS (Assertion Consumer Service) URL

Entity ID

DealRoom's Metadata (Entity ID/Metadata URL)

Start URL

Leave blank

Signed response

Checked

Name ID format

PERSISTENT

Name ID

Basic Information → Primary email

Click Continue.

Step 5: Map attributes in Google Admin

On the Attribute mapping page, click Add mapping for each row:

Google Directory attribute

App attribute

Basic Information → Primary email

Email

Basic Information → First name

FirstName

Basic Information → Last name

LastName

Optionally, add these two as well:

Google Directory attribute

App attribute

Contact Information → Phone number

PhoneNumber

Employee Details → Title

Title

App attribute names are case-sensitive. Type them exactly as shown.

Click Finish.

Step 6: Finish the integration in DealRoom

Return to the DealRoom tab and complete the form.

Title: a name your users will recognize, for example Google.

Attribute mapping:

DealRoom field

Value

Identifier

Email

Email

Email

First Name

FirstName

Last Name

LastName

Title

Title, only if you added it in Step 5

Phone

PhoneNumber, only if you added it in Step 5

Click Create to save the integration.

Step 7: Turn on the app for your users

New custom SAML apps are off by default in Google Workspace.

  1. In Google Admin, open the DealRoom app and click User access.

  2. Select ON for everyone, or turn it on only for specific groups or organizational units.

  3. Click Save.

Google notes that changes can take a few minutes to apply, and sometimes up to 24 hours.

Step 8: Test the sign-in

Sign out of DealRoom, then sign in with SSO as a user who has access to the app.

Troubleshooting

  • Extra spaces or missing characters. Check that no spaces or line breaks were added when you copied the URLs, and that the certificate includes its BEGIN and END lines.

  • "app not configured for user" or a 403 error from Google. The app isn't turned on for that user yet (Step 7), or the change hasn't taken effect.

  • User's name is missing or wrong. Check that the app attribute names in Google (Step 5) match the DealRoom attribute mapping exactly, including capitalization.

Still stuck? Contact your CSM or email support@dealroom.net.

Did this answer your question?