Set up SSO for GSuite (SAML)

  • Only Admins can use this feature

Setting up a new SSO  integration for GSuite with SAML

You need to be an admin on TravelPerk and GSuite to configure a new SSO integration following these steps:

  1. Go to Account Settings
  2. Select Integrations
  3. Find the SSO integration and click Set up
  4. Select SAML and click New integration

Once you've created a New integration, you'll need to configure it:

  1. Open your Google Admin Console and go to Apps 

    Screenshot_2020-11-16_at_10.40.21.png

  2. Select SAML Apps

    Screenshot_2020-11-16_at_10.41.03.png

  3. Click Add App and select Custom SAML App

    Screenshot_2020-11-16_at_10.41.51.png

  4. Give your new SAML app a name and add the configurations for your new SAML App as follows:

 

Your GSuite configurations for TravelPerk

  1. Copy the SSO URL and paste it into the IdP SSO service URL on TravelPerk
  2. Copy the Entity ID and paste it into the IdP entity ID on TravelPerk
  3. Copy the Certificate and paste it into the x509 cert on TravelPerk
  4. On your Google Admin Console, click Continue

    Screenshot_2020-11-16_at_10.42.30.png
    Screenshot_2020-11-11_at_20.16.22.png

 

TravelPerk configurations for your GSuite

  1. Copy the SP Assertion Consumer Service URL and paste it into the ACS URL on your Google Admin Console
  2. Copy the SP entity ID and paste it into the Entity ID on your Google Admin Console
  3. Optionally, you can set the Start URL with the following format: https://{yourcompanyname}.travelperk.com
  4. Make sure that:
    • the Signed response box is checked
    • the Name ID format is EMAIL
    • the Name ID is Basic information > Primary email
  5. Click Continue

    Screenshot_2020-11-16_at_11.20.27.png

  6. The Attributes must be exactly the same as the following table, including capital letters and punctuation

    Google Directory Attributes App Attributes
    First Name User.FirstName
    Last Name User.LastName
    Primary Email User.email

    Screenshot_2020-11-16_at_11.22.00.png

  7. Click Finish
  8. On TravelPerk, click Create integration

You must configure the User Access from GSuite to choose who can access TravelPerk, as it is OFF for everyone by default. 

For more information about customizing your SSO settings, see Customize SSO settings.

 

 

Was this article helpful?