Who can use this feature?
Plan: Call Center AI
Managed from: Krisp Admin Portal
User type: Team-level or Org Admin
Other: IdP account admin privileges
This article describes how to set up single sign-on (SSO) with Google Workspace for a single Krisp team or a Krisp Organization. SSO lets your users log in with their company credentials. Krisp SSO is based on SAML 2.0.
The Google Workspace setup is the same for both. The differences are where you start in the Krisp Admin Portal, and a few extra steps for Organizations to map your Google groups to Krisp teams and set the Org-level policy. These extra steps are grouped under Organization-specific settings.
Hint
For a general overview of Krisp SSO, see Getting started with Krisp SSO.
Open your Krisp SSO settings
Select the tab that matches your setup:
- In the Krisp Admin Portal, go to Settings >>> Team Settings >>> Security >>> Authentication.
- Turn on the Enable SSO toggle.
- Click SAML to open the Configure SAML panel.
- In the Krisp Admin Portal, go to Settings >>> Policies >>> Set Org-level Single Sign-on (SSO) Policy.
- Click Set up SSO to open the Single Sign-On sidebar.
You will copy values from this panel or sidebar into Google Workspace, and paste Google Workspace values back into it later. This article refers to it as your Krisp Settings. Keep it open while you work in Google Workspace.
Create a custom SAML app in Google Workspace
Add the app
- In the Google Admin console, go to Apps >>> Web and mobile apps.
- Click Add app >>> Add custom SAML app.
- On the App details step, enter an App name, for example Krisp. Optionally, add a Description and an App icon.
- Click Continue.
Copy the Google Identity Provider details
On the Google Identity Provider details step, go to Option 2: Copy the SSO URL, entity ID, and certificate and copy the following values into your Krisp Settings:
| Google Workspace field | Paste into (Krisp Settings) |
|---|---|
| SSO URL | Identity provider single sign on URL |
| Certificate | X-509 certificate. Use the copy icon, or download the certificate, open it in a text editor, and copy its contents. |
You do not need the Entity ID shown on this step. Click Continue.
Fill in the Service provider details
On the Service provider details step, enter the following values and continue:
| Google Workspace field | Value to enter |
|---|---|
| ACS URL | The Reply URL (Assertion Consumer Service URL) value from Krisp Settings |
| Entity ID | The Your team slug value from Krisp Settings |
| Start URL (optional) | The Single sign on URL value from Krisp Settings |
| Name ID format | |
| Name ID | Basic Information >>> Primary email |
Important
The Entity ID in Google Workspace must match the Your team slug, Audience URI, and Identity provider issuer values in Krisp Settings. If any of them differ, SSO sign-in fails.
Map the email attribute and groups
On the Attribute mapping step, map the user's email first:
- Under Attributes, click Add mapping.
- Under Google Directory attributes, select Basic Information >>> Primary email.
- Under App attributes, enter Email.
Then, set up Group membership. This sends each user's Google group membership to Krisp. Depending on your setup:
- Single team: optional. Without it, every user the app is turned on for in Google Workspace can access your Krisp team. With it, access is limited to members of the selected groups.
- Organization: required. Krisp uses these groups to assign users to Krisp teams.
To set up group membership:
- Under Group membership (optional), search for and select the Google groups that should have access to Krisp in the Google groups field.
- Under App attribute, enter Groups, and click Finish.
You manage the groups themselves, and their members, in the Google Admin console under Directory >>> Groups.
Complete the SSO setup in Krisp
Return to your Krisp Settings and fill in the remaining fields:
- Copy the Your team slug value into the Audience URI and Identity provider issuer fields.
- Confirm that the Identity provider single sign on URL and X-509 certificate fields contain the values you copied from Google Workspace.
- Click Configure for a single team, or Done for an Organization.
Turn on the app for your users
After you create the app, its User access is set to OFF for everyone by default. Users cannot sign in to Krisp with SSO until you turn it on.
- In the Google Admin console, go to Apps >>> Web and mobile apps and open the app you created.
- Click the User access section.
- Under Service status, select ON for everyone. To turn the app on only for specific users, select a group or organizational unit on the left first, then turn the service status on for it.
- Click Save.
Note that most changes take effect in a few minutes.
Test sign-in
Users the app is turned on for can now sign in to Krisp and authenticate through Google Workspace. Test sign-in with one or two accounts before rolling SSO out more widely.
Important
On the first sign-in, a user needs to enter the team slug instead of their email address. Once that first sign-in completes, signing in with the email address works as expected from then on.
For Organizations, a Google group appears in the Krisp Admin Portal only after one of its members signs in for the first time. Have one member of each group sign in, so every group you plan to map is available on the Mappings page.
How users get access
Users do not need an invitation. They gain access to Krisp by signing in with SSO. If you set up Group membership, only members of the selected groups get access. If you did not, every user the app's Service status is on for gets access.
Important
Google Workspace does not support SCIM provisioning for custom SAML apps, so the SCIM option in Krisp Settings cannot be used with Google Workspace.
To start using Krisp, each user needs to:
- Install the Krisp app on their device
- Use the Sign in with SSO flow after landing on account.krisp.ai, then authenticate in Google Workspace.
Organization-specific settings
The steps in this section apply only to Organizations. If you are setting up SSO for a single team, you can skip to Notes and limitations.
Map Google groups to Krisp teams
Once your groups have synced, assign them to the Krisp teams that should receive them.
- In the Krisp Admin Portal, go to Settings >>> Policies >>> Single Sign-On and click Manage mappings.
- Click Add team and add the Krisp teams you want to assign groups to.
- Click Assign IdP groups, then assign the relevant group to each team.
[IMAGE: Krisp Mappings page showing a team with a Google group assigned under IdP Groups. Highlight the Assign IdP groups button and the assigned group.]
Info
Users who are not part of any mapped group appear under Ungrouped users.
Manage unmapped groups and users
If the Mappings page shows a warning about groups missing assignment, click Manage unmapped groups. Users from unmapped groups do not have access to Krisp until their group is mapped to a team. From this view you can download a CSV of the affected addresses to check their details in Google Workspace, and assign or unassign groups to manage your seats accordingly.
Set the Org-level SSO policy
When your configuration and team mappings are ready, set the policy on the Single Sign-On page. The policy applies only to the teams selected in SSO mapping. Depending on your selection:
- Off: Org-level SSO becomes unavailable.
- Enabled: users can authenticate with SSO, and email authentication remains available.
- Enforced: all users, including Admins, must use SSO authentication only.
Important
You can set the policy to Enforced only if at least one Org Admin is currently signed in via SSO. This prevents Admins from being locked out. Enabling Org-level SSO automatically disables team-level SSO for the mapped teams.
Notes and limitations
- The team slug is modifiable, but it must be unique.
- If you belong to multiple Krisp teams with SSO, you cannot use your email instead of the team slug during sign-in.
- You can turn on Enforce SSO only if you, as an Admin, are currently signed in via SSO.
If SSO errors occur
If sign-in fails, capture the SAML assertion and send it to the Krisp team so we can investigate. If your users see an error while signing in, also share a network log file that captures the error.