Documentation

Google Workspace

Connect SURF to Google Workspace for user authentication, group and user provisioning, and corporate storage of downloads.

Requirements

ItemRequiredNotes
DomainYesExpected to be accounts.google.com
SSO LinksNoOptional
Google Workspace credentialsNoNeeded only if you want to import and provision groups and users from your workspace into SURF

Step 1: Create the OAuth credentials in Google Cloud

Needed only if you are provisioning groups and users. Skip to Step 2 if you are configuring the domain alone.

  1. Go to https://console.cloud.google.com
  2. Create a new project.
  3. Under Credentials, click + Create Credentials.
  4. Select OAuth client ID.
  5. Give the credentials a name.
  6. Under Application type, select Web application.
  7. Click ADD URI and enter https://admin.surf-admin.link/app/gws, then press Create.
  8. Download the application credentials as JSON.

Step 2: Configure the integration in SURF

  1. Log in to the SURF Admin console and go to Settings → Integrations.
  2. Find Google WorkSpace and add the integration.
  3. Complete the setup dialog:
FieldValue
Domainaccounts.google.com
SSO LinksOptional
Google Workspace credentialsThe OAuth2 credentials JSON downloaded at Step 1, step 8
  1. Click Submit.

Related pages

Google Drive Integration: routing user downloads to a corporate Google Drive folder. Full Browser only.

Troubleshooting

SymptomCheck
Redirect error during authorisationThe URI https://admin.surf-admin.link/app/gws is missing from the OAuth client, or has not propagated yet
Groups and users do not importThe Google Workspace credentials field was left empty. It is optional for sign-in but required for provisioning.
Domain rejectedThe domain must be accounts.google.com, not your own Workspace domain

For anything not covered here, contact the SURF support team.