Overview
You can enable SAML-based Single Sign-On for the Persona Dashboard via Google SSO via your Google Workspace account by following this guide.
By default, users can choose to login through SAML or via email and password. SAML enforcement can be configured by navigating to Organization > Authentication for a user with Admin permissions.
Retrieve your Organization Slug
Log in to your Persona dashboard as a user with Admin permissions.
- Navigate to Organization > Authentication.
- Under Single sign-on, you’ll find your Organization Slug.
Make note of your Organization Slug. You’ll need it in the steps below.
Steps in Google Workspace
- From Google Workspace admin console, navigate to Menu > Apps > Web and mobile apps.
- Click on Add app and select Add custom SAML app.
- Fill out App details. Click CONTINUE.
- Download IdP metadata (Option 1). Click CONTINUE
- Add service provider details, replace
<ORGANIZATION-SLUG>from the first section- ACS URL:
https://withpersona.com/saml/<ORGANIZATION-SLUG>/acs - Entity ID:
https://withpersona.com/saml/<ORGANIZATION-SLUG>/metadata
- ACS URL:
- Leave Name ID format as
UNSPECIFIEDand Name ID asBasic Information > Primary emailand click CONTINUE. - Leave attributes and group membership as-is. Click FINISH.
- You’ll now see your SAML app added. In this example, we named our Persona Application “withpersona SSO”.

- If you haven’t already downloaded the metadata, click on Download Metadata.
Steps in the Persona Dashboard
- Log in to your Persona dashboard as a user with Admin permissions
- Navigate to Organization > Authentication.
- Under Single sign-on, click Manage.
- Enter the Metadata you obtained from the last step in the previous section.
- Copy the metadata into Provide the raw Metadata XML IdP details section.
- Click Parse metadata.
Renewing an expiring SAML SSO certificate
Google signing certificates have a five-year lifetime. If the certificate expires before it is replaced, your users will not be able to sign in to Persona through Google SSO until a new certificate is in place.
Unlike Okta and Azure, Google Workspace does not publish a metadata URL for custom SAML apps, so Persona cannot pick up a renewed certificate on its own. Every rotation requires re-uploading the updated metadata to Persona.
Generate a new certificate in Google Workspace
- Sign in to the Google Admin console as a super administrator.
- Go to Menu > Security > Authentication > SSO with SAML applications.
- Click Add another certificate. Google generates the new certificate for you.
Assign the new certificate to your Persona app
- Go to Menu > Apps > Web and mobile apps and click your Persona SAML app to open its Settings page.
- Click Service provider details.
- Click the Down arrow and choose the new certificate.
- Download the updated IdP metadata for the app.
Refresh the metadata in Persona
- Log in to your Persona dashboard as a user with Admin permissions.
- Navigate to Organization > Authentication.
- Under Single sign-on, click Manage.
- Copy the updated metadata into the Provide the raw Metadata XML IdP details section.
- Click Parse metadata.
Access to SAML-based SSO with Google by plan
| Startup Program | Essential Plan | Growth Plan | Enterprise Plan | |
|---|---|---|---|---|
| SAML-based SSO with Google | Available | Available | Available | Available |