Skip to main content

Google SSO Configuration (SHA-256)

This article explains how to configure Google Workspace SSO for Education Perfect, including sending metadata, completing the SAML app setup, matching existing user accounts, and troubleshooting common errors.

This article details how to configure Google Workspace for use with Education Perfect’s Single Sign-On (SSO) system.

Please note that we now support logging in with Google directly, and it may not be necessary to set up an integration at all!

Please see our help doc here or contact us for more details.

Sending us your metadata

  1. From the G-Suite Admin console Home page, go to Apps and then SAML apps.

  2. Click Add App -> Add Custom SAML APP

  3. Add anything as the App name, click Continue

  4. Download the metadata and send this to us at [email protected] along with a test account

  5. Cancel out of adding this App

Secondary Steps

Once you get a response from us, please do the following:

  1. From the G-Suite Admin console Home page, go to Apps and then SAML apps.

  2. Click Add App -> Add Custom SAML APP

  3. Add ‘Education Perfect’ as the App name, click Continue twice

  4. On the Service Provider Details screen, enter the following:

  5. Entity ID: Issuer: as provided by us (please note that we are unable to provide this value until after we have loaded your metadata from step 4)

  6. Signed Response: Leave unchecked.

  7. Name ID Format: EMAIL (This might need to be PERSISTANT if 403 errors occur during testing)

  8. Name ID: Basic Information, Primary Email. Click Next

  9. On the Attribute Mapping screen, click Finish

  10. Click User Access and then turn it on for everyone (as below) or for specific organizational units as appropriate, and click Save. As noted, it may take up to 24 hours for this change to take effect for all users.

    Google admin options

    If you do not turn the Education Perfect app on for your users they will see the following error message when trying to log into Education Perfect:

    403 thats an error
  11. Once this is done, please email us and let us know so that we may commence testing

  12. Please note, that users will need to be signed into their school-affiliated Google account in order to be able to log in via SSO(or at the least, not signed into a different Google account)

Other Errors

500

500 thats an error

This error generally means something is wrong with the configuration and may require support from Google directly. However it may be worth checking that your SAML certificate has not expired first.

Did this answer your question?