Configure SAML-based single sign-on between Google Workspace and CodeRabbit from your organization’s account management page.
Use this guide to configure Google Workspace as the identity provider for your CodeRabbit Enterprise organization. The account management SSO wizard guides you through domain verification, Google Workspace SAML app setup, testing, and activation.After SSO is activated, users with a verified email domain must sign in to CodeRabbit through Google Workspace.
Critical: You must have an invitation to your CodeRabbit organization from your CodeRabbit account team before starting this setup.
Organization admin access in the CodeRabbit account management page
Access to the Google Admin Console
Permission to create and configure custom SAML apps in Google Workspace
Access to your DNS provider if your email domain still needs verification
The users, groups, or organizational units that should be allowed to sign in through Google Workspace
If you do not see the Security section or the Start configuration button in your organization profile, contact your CodeRabbit account team. Your organization must be prepared for self-serve SSO before the account management SSO wizard appears.
Accept your CodeRabbit organization invitation and sign in to the account management page. Open the organization switcher, find the invited organization, and click Manage.In the organization profile, select Security, and click Start configuration.
2
Add and verify your email domain
In Domains, enter the email domain that should use Google Workspace for CodeRabbit sign-in, then click Add.If the wizard asks you to add a DNS record, add the generated TXT record in your DNS provider and wait for the domain to show Verified before continuing.
Continue after the email domain shows Verified
3
Select Google Workspace
In Connection, select Google Workspace as the SAML identity provider.
Select Google Workspace as the identity provider
4
Create the custom SAML app in Google Workspace
The account management SSO wizard lists the Google Admin Console steps you need to complete.
Review the Google Workspace app creation steps
In the Google Admin Console, go to Apps -> Web and mobile apps, click Add app, then select Add custom SAML app.
Select Add custom SAML app in Google Admin Console
In App details, enter a clear app name such as CodeRabbit. The description and icon are optional.
Enter a clear app name for the custom SAML app
5
Download and upload the IdP metadata
In the Google custom SAML app setup, download the Google IdP metadata.
Download the Google IdP metadata file
Return to the account management SSO wizard. In Configure Google Workspace, keep Add via metadata selected, upload the Google metadata XML file, and continue.
Upload the Google IdP metadata file
6
Configure service provider details
In the account management SSO wizard, copy the ACS URL and Entity ID values.
Copy the service provider values from the account management SSO wizard
In the Google custom SAML app setup, paste the values into the matching fields:
Google field
Value
ACS URL
Copy from the account management SSO wizard
Entity ID
Copy from the account management SSO wizard
Start URL
Leave blank
Signed response
Leave unchecked unless your CodeRabbit account team instructs otherwise
Name ID format
EMAIL
Name ID
Basic Information > Primary email
Paste the CodeRabbit service provider values into Google Workspace
7
Map SAML attributes
The account management SSO wizard lists the attributes CodeRabbit expects from Google Workspace.
Review the required Google Workspace attribute mappings
In the Google custom SAML app setup, add the following attribute mappings:
Google directory attribute
App attribute
Primary email
email
First name
firstName
Last name
lastName
Add the required attribute mappings in Google Workspace
8
Turn on the SAML app for users
After the custom SAML app is created, open its Service status settings and turn the app on for the users, groups, or organizational units that should be allowed to sign in to CodeRabbit.The example below shows ON for everyone. Use the access scope that matches your rollout plan.
Turn on service access for the users who should sign in through Google Workspace
9
Test the SSO connection
In Test, click Open test URL and complete the Google Workspace sign-in flow with a user who has access to the custom SAML app and whose email matches your verified domain.Return to the account management SSO wizard and click Refresh logs until the latest test result shows Success. Do not activate SSO while the latest result is Pending or failed.
Confirm the SSO test result succeeds before activation
10
Activate SSO
In Activate, review the activation message and click Activate SSO.
Activation changes sign-in behavior for the verified domain. After activation, users with that email domain must sign in to CodeRabbit through Google Workspace.