WiseStamp for IT › Google Workspace › Step 6 of 12 — SSO with Google Workspace (SAML)
Plan requirement: Platform or Enterprise.
Note: the pricing page lists SSO under Platform and Enterprise, while the "Account Login Methods" help-center article lists "Legacy Enterprise, Advance, and Enterprise." These are not in conflict — Advance is the previous commercial name for the Platform plan. SSO is available on Platform (formerly Advance) and Enterprise.
Scope note: SSO governs admin sign-in to the WiseStamp web app. Employees do not log into WiseStamp; they receive signatures automatically and use the Employee Hub. SSO is not required to deploy signatures.
Who does what
Step | Owner |
Create the SSO domain in WiseStamp and issue the Provider ID | WiseStamp support |
Create and configure the WiseStamp custom SAML app in Google Workspace | You (IT) |
Send IdP SAML metadata to WiseStamp | You (IT) |
Apply metadata / finalize the SSO domain | WiseStamp support |
Start by contacting WiseStamp support to create the SSO domain and obtain your Provider ID (used as the SAML RelayState).
SAML endpoints (WiseStamp service provider)
Use these when configuring the custom SAML app in Google Workspace:
Field | Value |
ACS URL | |
Entity ID | |
Default RelayState | Your Provider ID (from WiseStamp support) |
Name ID format |
These values are taken directly from the WiseStamp help center’s Google Workspace SSO walkthrough.
Procedure — Google Workspace as IdP
Sign in to the Google Workspace Admin console.
Go to Apps > Web and mobile apps > Add app > Add custom SAML app.
Enter the app name WiseStamp and click CONTINUE twice.
Configure service provider information:
Entity ID: https://webapp.wisestamp.com
Default RelayState: your Provider ID from WiseStamp support.
Name ID format: EMAIL.
Click CONTINUE, then FINISH.
Set User access permissions (which org units / groups may use SSO).
Click DOWNLOAD METADATA and send the file to WiseStamp support.
WiseStamp applies the metadata and finalizes your SSO domain.
Validation
After WiseStamp confirms the SSO domain is live, go to https://webapp.wisestamp.com/login.
Initiate SSO sign-in; confirm redirect to Google and back, landing authenticated in WiseStamp.
Confirm a user with access can sign in and a user without access is denied.
Other supported IdPs (reference)
The knowledge base also documents full click-paths for Okta and OneLogin, using the same ACS URL and Provider ID/RelayState pattern. Audience/Entity ID values vary slightly per provider in the source — for Google Workspace, use the Entity ID https://webapp.wisestamp.com shown above.