> ## Documentation Index
> Fetch the complete documentation index at: https://docs.variable.global/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up SSO with Google Workspace

> Create an OAuth client in Google Cloud for your Google Workspace and send us the credentials to switch on single sign-on

Google Workspace sign-in runs through a Google Cloud project. You create an **OAuth client** there — think of it as issuing Variable a badge that lets it ask Google "who is this person?" — and the project's consent screen decides which Google accounts may use it.

You need a Google Workspace **super admin**, or an admin who can create projects in your organization's Google Cloud. Read the [single sign-on overview](/docs/sso/overview) first if you have not verified your domain in Variable.

## Create or choose a project

1. Open the [Google Cloud console](https://console.cloud.google.com) signed in with a Workspace admin account.
2. Use the project picker to select an existing project, or choose **New project** and name it `Variable SSO`. Make sure the project belongs to your Workspace organization, not to a personal account.

## Configure the consent screen

The consent screen is what people see when Google asks them to allow Variable to read their name and email.

1. Go to **Google Auth Platform** → **Branding** (older consoles: **APIs & Services** → **OAuth consent screen**) and complete the app name, support email and developer contact.
2. Under **Audience**, set the user type to **Internal**. This restricts sign-in to accounts in your Workspace organization. It is the control that keeps outside Google accounts out, so do not choose **External** unless you have discussed it with us.
3. Under **Data Access**, add the scopes `openid`, `.../auth/userinfo.email` and `.../auth/userinfo.profile`. These are the non-sensitive defaults and need no Google verification review.

<Warning>
  With the audience set to **External**, any Google account can attempt to sign in and Google may show an "unverified app" warning. Internal apps skip both.
</Warning>

## Create the OAuth client

1. Go to **Google Auth Platform** → **Clients** (older consoles: **APIs & Services** → **Credentials** → **Create credentials** → **OAuth client ID**) and select **Create client**.
2. Set **Application type** to **Web application** and name it `Variable`.
3. Under **Authorized redirect URIs**, add:

   ```text theme={"system"}
   https://app.variable.global/api/auth/google/callback
   ```

   It must match exactly, including `https` and no trailing slash. Leave **Authorized JavaScript origins** empty.
4. Select **Create**, then copy the **Client ID** and **Client secret**. Keep the secret out of shared documents and chat.

## Send us the credentials

Send us the following through an agreed-upon secure channel:

* Provider: Google
* Client ID
* Client secret
* The email domains to cover, each verified in Variable, including your primary Workspace domain
* A contact who can test the sign-in

Google reports your organization's primary domain for every account, including people whose address is on a secondary domain. Variable only accepts an account whose primary domain is linked to the connection, so include it even if nobody signs in with it.

We confirm once it is switched on. Google client secrets do not expire on their own, but rotate yours on your usual schedule and send us the new one before you disable the old.

## Test it

1. Open a private browser window and go to `https://app.variable.global`.
2. Enter your work email and continue. You are sent to Google.
3. Choose your Workspace account. You land back in Variable.

Variable passes your domain to Google as a hint, so the account picker leans toward your Workspace accounts. The hint is a convenience, not a lock. The boundary is enforced twice: the **Internal** audience keeps outside accounts at Google, and Variable rejects an account whose email Google has not verified or whose Workspace domain is not linked to your connection.

## Troubleshooting

| Google or Variable says | Cause | Fix |
| :- | :- | :- |
| `Error 400: redirect_uri_mismatch` | The redirect URI on the OAuth client differs from the one above | Correct it under **Authorized redirect URIs**; changes can take a few minutes to apply |
| `Error 401: invalid_client` | Wrong client ID, or the client was deleted | Recopy the client ID from the **Clients** page and send it to us |
| `Error 403: org_internal` | The person signed in with an account outside your Workspace | Sign in with the Workspace account |
| `Access blocked: ... has not completed the Google verification process` | Audience is set to **External** | Switch the audience to **Internal** |
| Back on the sign-in page with no message | The Google account is not the address that was typed, the secret sent to us is wrong, your primary Workspace domain is not linked to the connection, or the sign-in did not start on Variable's sign-in page in the same browser | Start from Variable's sign-in page and sign in with the same address. If it happens again, contact us: we can check the secret and the linked domains |
| A setup screen asking for a company name | Signed in, but not invited to Variable | See [invite people first](/docs/sso/overview#invite-people-first) |

## Restrict who can sign in (optional)

To limit Variable to specific people, open the Admin console at [admin.google.com](https://admin.google.com), go to **Security** → **Access and data control** → **API controls** → **Manage third-party app access**, add the OAuth client by its client ID, and set access to **Limited** or **Specific Google Workspace groups**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.