This guide walks you through integrating Humand as a SAML-based application within your Google Workspace environment, enabling secure and seamless Single Sign-On (SSO) for your users.
Accessing the Google Admin Console
1. Sign in to the Google Admin Console using a super administrator account.
2. From the Admin Console dashboard, navigate to:
- Apps Web and mobile apps
3. Click Add App > Add custom SAML app.
Adding details
- App Name: Humand-EndUser-SSO (or any name you prefer).
- (Optional) Upload an app icon for easier identification.
- Click Continue.
Google Identity Provider (IdP) Information
- On the Google IdP Information page, click Download Metadata.
- Save the metadata file; you'll need to share this with Humand later.
-
Click Continue.
Service Provider Details
1. ACS URL:
https://api-prod.humand.co/api/v1/sso-saml/callback?to=INSTANCE_I D
2. Entity ID:
https://api-prod.humand.co/api/v1/sso-saml/INSTANCE_ID
3. Start URL: (Optional) Leave blank unless specified by your IT policy.
4. Name ID Format:
EMAIL
5. Name ID:
Basic Information Primary Email
Click on "Continue".
Assigning Users
1. Navigate to the User access section of the newly created app.
2. Click Edit.
3. Choose ON for everyone or select specific organizational units/groups as needed.
4. Click Save.
Users must be assigned to the application to access Humand via SSO. Unassigned users will encounter access errors.
Share Metadata with Humand
Locate the metadata file you downloaded in Step 3. Email the file to: help@humand.co CC your Humand Onboarding Leader or Account Manager. Specify in the email that this metadata is for the End-User Portal.
Configure SSO for the Admin/Back Office Portal
To enable SSO for Humand’s Admin/Back Office portal:
1. Repeat Steps 1–5 to create a new custom SAML app.
2. Use the following values:
- ACS URL: https://api-prod.humand.co/api/v1/backoffice/sso-saml/callback?to=INST ANCE_ID
- Entity ID: https://api-prod.humand.co/api/v1/backoffice/sso-saml/INSTANCE_ID
Email the new metadata file to: help@humand.co
Specify in the email that this metadata is for the Admin/Back Office Portal.
Final Considerations
- If you encounter any issues during the setup, contact: help@humand.co
- Once both Humand and your team have completed the configuration, Humand will notify you to begin testing.
- By default, all assigned users will authenticate via SSO.
- If certain users need to bypass SSO and use traditional username/password authentication, provide their details to: help@humand.co