Google Workspace
Connect SURF to Google Workspace for user authentication, group and user provisioning, and corporate storage of downloads.
Requirements
| Item | Required | Notes |
|---|---|---|
| Domain | Yes | Expected to be accounts.google.com |
| SSO Links | No | Optional |
| Google Workspace credentials | No | Needed only if you want to import and provision groups and users from your workspace into SURF |
Step 1: Create the OAuth credentials in Google Cloud
Needed only if you are provisioning groups and users. Skip to Step 2 if you are configuring the domain alone.
- Go to
https://console.cloud.google.com - Create a new project.
- Under Credentials, click + Create Credentials.
- Select OAuth client ID.
- Give the credentials a name.
- Under Application type, select Web application.
- Click ADD URI and enter
https://admin.surf-admin.link/app/gws, then press Create. - Download the application credentials as JSON.
Step 2: Configure the integration in SURF
- Log in to the SURF Admin console and go to Settings → Integrations.
- Find Google WorkSpace and add the integration.
- Complete the setup dialog:
| Field | Value |
|---|---|
| Domain | accounts.google.com |
| SSO Links | Optional |
| Google Workspace credentials | The OAuth2 credentials JSON downloaded at Step 1, step 8 |
- Click Submit.
Related pages
Google Drive Integration: routing user downloads to a corporate Google Drive folder. Full Browser only.
Troubleshooting
| Symptom | Check |
|---|---|
| Redirect error during authorisation | The URI https://admin.surf-admin.link/app/gws is missing from the OAuth client, or has not propagated yet |
| Groups and users do not import | The Google Workspace credentials field was left empty. It is optional for sign-in but required for provisioning. |
| Domain rejected | The domain must be accounts.google.com, not your own Workspace domain |
For anything not covered here, contact the SURF support team.
