Test in a staging Google app before enforcing SSO on production users. Keep at least one break-glass owner account with a non-SSO recovery path.
Prerequisites
- Google Workspace admin access
- Antsfield workspace owner role
- Enterprise plan with SAML enabled
Set up Google Workspace SAML
1
Open Antsfield Security settings
In Antsfield, go to Settings → Security and click to configure SAML Single Sign-On. Select Google Workspace as your identity provider.
2
Create a SAML app in Google Admin
In the Google Admin console, go to Apps → Web and mobile apps → Add app → Add custom SAML app.Name the app Antsfield and continue through the setup wizard.
3
Copy Antsfield ACS URL and Entity ID
From the Antsfield SAML setup modal, copy:
- ACS URL (Assertion Consumer Service URL)
- Entity ID (SP Entity ID / Audience URI)
4
Copy the metadata URL
Step 4: Copy the metadata URL
In the Google SAML app setup, Google provides an IdP metadata URL (or downloadable metadata XML).- Copy the metadata URL from Google.
- In Antsfield Settings → Security, paste the metadata URL into the SAML configuration form.
- Save the configuration in Antsfield.
5
Map attributes
In Google, map SAML attributes so Antsfield receives:
The email attribute must match a user allowed to access Antsfield.
6
Assign users and test
In Google Admin, assign the Antsfield SAML app to users or groups who should sign in.
- Sign out of Antsfield.
- On the login page, click Sign in with SAML (or use your IdP-initiated flow).
- Confirm you land in the correct workspace.

