> Full SurrealDB documentation index: https://surrealdb.com/docs/llms.txt

# Google Workspace

Configure Google Workspace as an identity provider for single sign-on in SurrealDB. Create an OAuth client in Google Cloud and add a Google Workspace connection in SurrealDB Studio.

Connect Google Workspace to SurrealDB to allow members of your organisation to sign in with their Google accounts. You create an OAuth client in the Google Cloud console, then enter its details in a new connection in SurrealDB Studio.

Before you start, [verify the email domain](/docs/manage/enterprise/single-sign-on.md#step-1-verify-an-email-domain) your company uses. You also need access to the Google Cloud console for a project in your Google Workspace organisation.

## Step 1: Prepare the Google Cloud project

1. In the Google Cloud console, enable the **Admin SDK API** for your project.
2. Open **Google Auth Platform** and configure the OAuth consent screen with the audience set to **Internal**.
3. Add `surrealdb.com` as an authorised domain.

An internal consent screen limits sign-in to accounts in your Google Workspace organisation.

## Step 2: Create an OAuth client

1. Open **APIs and services**, then **Credentials**.
2. Select **Create credentials**, then **OAuth client ID**.

![The Credentials page in the Google Cloud console, with the Create credentials menu at the top.](~/assets/img/surrealdb/manage/enterprise-sso-google-1.webp)

3. Set **Application type** to **Web application**.
4. Enter a name, for example `SurrealDB`. Only you see this name in the console.
5. Under **Authorised JavaScript origins**, add `https://auth.surrealdb.com`.
6. Under **Authorised redirect URIs**, add `https://auth.surrealdb.com/login/callback`.
7. Select **Create**.

![The Create OAuth client ID form in the Google Cloud console, with the application type, name, JavaScript origin and redirect URI filled in.](~/assets/img/surrealdb/manage/enterprise-sso-google-2.webp)

Google then shows the client ID and the client secret. Copy both, or select **Download JSON** to save them.

> [!IMPORTANT]
> Google shows the client secret only once. After you close the dialogue, you cannot view or download it again, and you must create a new secret.

![The OAuth client created dialogue in the Google Cloud console, showing the client ID and the client secret.](~/assets/img/surrealdb/manage/enterprise-sso-google-3.webp)

It can take from five minutes to a few hours for the new client to take effect.

## Step 3: Add the connection in SurrealDB

1. Open **Single sign-on** in your enterprise and add a new connection.
2. Select **Google Workspace**.
3. Under **Name the connection**, enter a **Display name**. Members see this name on the sign-in screen.
4. Under **Enter the Google Workspace details**, enter:
    - **Google Workspace domain**: the primary domain of your Workspace, for example `example.com`.
    - **Client ID**: the client ID from step 2.
    - **Client secret**: the client secret from step 2.
5. Under **Route sign-in domains**, select the verified domains to send to this connection. This is optional, and you can change it later.
6. Select **Create connection**.

The **Set up Google Workspace** section of the form shows the JavaScript origin, the authorised domain and the redirect URI, with a copy button beside each, if you need them again.

![The New Google Workspace connection form in SurrealDB Studio, with the display name, Google Workspace domain, client ID, client secret and a routed domain filled in.](~/assets/img/surrealdb/manage/enterprise-sso-google-4.webp)

SurrealDB stores the client secret securely and does not show it again.

## Next steps

If you did not route a domain when you created the connection, [route one now](/docs/manage/enterprise/single-sign-on.md#step-3-route-domains-to-the-connection). Then [choose the applications](/docs/manage/enterprise/single-sign-on.md#step-4-choose-the-applications) that people can sign in to with this connection.
