This guide is for Google Workspace administrators. Replace {your-portal-domain} with your Marvia portal host, for example acme.getmarvia.com. Marvia connects to Google Workspace using SAML 2.0. OpenID Connect is not used for this integration.
Create a Custom SAML App in Google Workspace, then send Marvia the values listed at the end of this page. After we save them, users can sign in with the SSO button on your Marvia login page.
1. Create the SAML App
In the Google Admin Console (admin.google.com), go to Apps → Web and mobile apps.
Click Add App → Add custom SAML app.
Enter an App name, for example
Marvia.(Optional) Add a description and upload the Marvia logo, then click Continue.
2. Configure SAML Settings
On the Google Identity Provider details step, click Continue (you will collect the provider details in Step 5).
On the Service provider details step, enter these values:
Google field | Value |
ACS URL |
|
Entity ID |
|
Start URL |
|
Signed Response | Checked |
Name ID format |
|
Name ID |
|
(Optional) You can also click Optionally parse metadata and import Marvia's metadata from: https://{your-portal-domain}/saml/metadata
Click Continue.
3. Attribute Mapping
Map the standard user attributes in Google Workspace to Marvia:
Under Attributes, click Add mapping.
Configure the following custom attribute fields:
Google Workspace attribute | App attribute |
|
|
|
|
|
|
Groups (optional)
If users should be placed in Marvia groups automatically:
Under Group membership, click Add mapping.
Select the Google Workspace groups that should sync.
Set the App attribute name to
groups.
Locations (optional)
If you use location or branch access in Marvia, add:
Google Workspace attribute | App attribute |
Select the attribute containing the location (e.g., |
|
Click Finish.
4. Turn On Access for Users
By default, newly created SAML apps are turned off for all users.
In the app overview page, select User access.
Select the Organizational Unit (OU) or group you want to grant access to.
Change Service status to ON for everyone (or ON for selected OUs).
Click Save.
5. Send these values to Marvia
Return to the app's Google Identity Provider details page (or click Download Metadata from the app overview) and send Marvia:
Entity ID (Identity Provider Issuer)
SSO URL (Identity Provider Single Sign-On URL)
Certificate: Download the Certificate, open it in a text editor, and copy the full text including the
-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----lines.
Once we have saved these on our side, users can sign in with the SSO button on your Marvia login page.
