When using SAML SSO with Sevalla, login must always be initiated from Sevalla. Logging in directly from your Identity Provider (IdP) is not supported.IdPs only support one active session per browser. If you have multiple Google Workspace accounts and are logged into one, attempting to log into another through Sevalla will result in an error. To switch accounts, log out of Google Workspace or use your browser’s Incognito/Private mode.
Enable SSO in Sevalla
When you set up SAML SSO, you can navigate away from the SSO setup at any stage to store your progress and return later. In Sevalla, go to your Settings > Single sign-on, and click Enable.

Create the app in Google Workspace
In Sevalla, the Create SAML app tab provides all the information you need to set up your SAML app within Google Workspace. The following steps explain where to add this information.



Sevalla setup
In Sevalla, on Create SAML app, click Continue so that you are on the Sevalla setup page. We will return to the Create SAML app tab in the next step when adding the service provider details to Google Workspace.Email domain
In the Domain name, enter the email domain users will use to sign in using SAML SSO, and click Add domain. Only Sevalla accounts with an email address matching the verified domain can authenticate via SAML. For example, if SAML is enabled forexample.com, only users with an @example.com email address will be able to sign in for that company.
Each email address can only be linked to one SAML configuration in Sevalla. This means a domain (e.g.,
example.com) can be associated with only one company at a time. Similarly, each Sevalla user can use SAML authentication for a single company only.
Set up Sevalla SAML
In Google Workspace, the Google Identity Provider details tab provides all the information you need to set up SAML in Sevalla.
- SSO URL: Copy and paste the SSO URL from Google Workspace.
- Entity ID: Copy and paste the Entity ID from Google Workspace.
- Public certificate: Copy and paste the contents of the Certificate from Google Workspace.
Add the service provider details in Google Workspace
In Sevalla, within Single sign-on, ensure you are on the Create SAML app tab. Within Google Workspace, click Continue to the Service provider details tab and complete as follows:- **ACS URL: **Copy and paste the SSO/ACS URL from Sevalla.
- Entity ID: Copy and paste the Entity ID from Sevalla.
- Start URL: Copy and paste the Start URL from Sevalla.
- Signed response: Select this option.
- Name ID format: EMAIL.
- Name ID: Basic Information > Primary email.

Map your Google Workspace attributes
Within Attribute mapping, you can add the first name, last name, and email to the login credentials. Complete these as follows, and click ADD MAPPING after each entry:| Google directory attributes | App attributes |
|---|---|
| Fiest name | firstName |
| Last name | lastName |
| Primary email |

Set up user access to the Google Workspace app
In Google Workspace, in the Admin app, go to Apps > Web and mobile apps, select the Sevalla application, and click User access.

Test the authentication in Sevalla
You cannot enable SAML SSO within Sevalla without first testing the authentication. In Sevalla, within Single sign-on, click Continue until you are on the Test and finish tab, and click Test authentication. A notification appears if the test was successful or if the test fails. If the test fails, click Back and check your SAML settings within your IdP and within Sevalla. If the test is successful and you want to enable SAML, click Save and set SSO live.






