Skip to main content
Set up SAML 2.0 single sign-on between your identity provider and CloudThinker. Start the wizard at Admin Settings → Identity and access → Setup SSO and choose SAML 2.0; the SP Metadata step shows the ACS URL, SP Entity ID, and SP Metadata URL you paste into your provider.

Prerequisites

  • A verified email domain and an eligible plan — see Single Sign-On
  • Admin access to your identity provider
On the wizard’s IdP Config step, paste your provider’s metadata URL into the Import field to auto-fill IdP Entity ID, SSO URL, and IdP Certificate in one step.

Provider setup

1

Create a custom SAML app

Go to admin.google.comApps → Web and mobile apps → Add app → Add custom SAML app. Name it CloudThinker and click Continue.
2

Download the IdP metadata

On the Google IdP information screen, download the IdP metadata XML or note the SSO URL, Entity ID, and the X.509 Certificate. Click Continue.
3

Enter CloudThinker's SP details

Copy the values from CloudThinker’s SP Metadata step:Click Continue.
4

Configure attribute mapping

Click Finish, then set the app’s access to On for everyone (or target specific organizational units).
5

Finish in CloudThinker

On the IdP Config step, enter the Entity ID, SSO URL, and Certificate from Google (or use Import with the metadata URL). Click Create Connection.

Troubleshooting

The ACS URL in your provider must exactly match CloudThinker’s ACS URL — including https:// and no trailing slash.
Your provider isn’t sending firstName and lastName. Add them in the attribute mapping table for your provider above.
Paste the full X.509 certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. If your provider rotated its certificate, update IdP Certificate on the connection.
The SP Entity ID configured in your provider must exactly match CloudThinker’s SP Entity ID — the comparison is case-sensitive.

Next steps

Test and Enforce SSO

Test the connection, turn on Require SSO, and choose a provisioning mode

SCIM Provisioning

Sync users and groups automatically from your identity provider