Skip to main content
Use this guide to configure Google Workspace as the identity provider for your CodeRabbit Enterprise organization. The account management SSO wizard guides you through domain verification, Google Workspace SAML app setup, testing, and activation. After SSO is activated, users with a verified email domain must sign in to CodeRabbit through Google Workspace.

Before you start

Make sure you have:
  • Critical: You must have an invitation to your CodeRabbit organization from your CodeRabbit account team before starting this setup.
  • Organization admin access in the CodeRabbit account management page
  • Access to the Google Admin Console
  • Permission to create and configure custom SAML apps in Google Workspace
  • Access to your DNS provider if your email domain still needs verification
  • The users, groups, or organizational units that should be allowed to sign in through Google Workspace
If you do not see the Security section or the Start configuration button in your organization profile, contact your CodeRabbit account team. Your organization must be prepared for self-serve SSO before the account management SSO wizard appears.

Set up Google Workspace self-serve SSO

1

Open the account management SSO wizard

Accept your CodeRabbit organization invitation and sign in to the account management page. Open the organization switcher, find the invited organization, and click Manage.In the organization profile, select Security, and click Start configuration.
2

Add and verify your email domain

In Domains, enter the email domain that should use Google Workspace for CodeRabbit sign-in, then click Add.If the wizard asks you to add a DNS record, add the generated TXT record in your DNS provider and wait for the domain to show Verified before continuing.
Domain verification step showing the email domain verified

Continue after the email domain shows Verified

3

Select Google Workspace

In Connection, select Google Workspace as the SAML identity provider.
Identity provider selection screen with the Google Workspace tile highlighted

Select Google Workspace as the identity provider

4

Create the custom SAML app in Google Workspace

The account management SSO wizard lists the Google Admin Console steps you need to complete.
Account management SSO wizard showing Google Workspace custom SAML app creation steps

Review the Google Workspace app creation steps

In the Google Admin Console, go to Apps -> Web and mobile apps, click Add app, then select Add custom SAML app.
Google Admin Console Add app menu with Add custom SAML app highlighted

Select Add custom SAML app in Google Admin Console

In App details, enter a clear app name such as CodeRabbit. The description and icon are optional.
Google Admin Console custom SAML app details screen with a generic CodeRabbit app name

Enter a clear app name for the custom SAML app

5

Download and upload the IdP metadata

In the Google custom SAML app setup, download the Google IdP metadata.
Google Admin Console Google Identity Provider details screen with Download Metadata highlighted

Download the Google IdP metadata file

Return to the account management SSO wizard. In Configure Google Workspace, keep Add via metadata selected, upload the Google metadata XML file, and continue.
Account management SSO wizard showing the uploaded Google IdP metadata file

Upload the Google IdP metadata file

6

Configure service provider details

In the account management SSO wizard, copy the ACS URL and Entity ID values.
Account management SSO wizard showing the ACS URL and Entity ID fields redacted

Copy the service provider values from the account management SSO wizard

In the Google custom SAML app setup, paste the values into the matching fields:
Google Admin Console service provider details screen with the ACS URL and Entity ID redacted

Paste the CodeRabbit service provider values into Google Workspace

7

Map SAML attributes

The account management SSO wizard lists the attributes CodeRabbit expects from Google Workspace.
Account management SSO wizard showing the expected Google Workspace SAML attributes

Review the required Google Workspace attribute mappings

In the Google custom SAML app setup, add the following attribute mappings:
Google Admin Console attribute mapping screen showing email, firstName, and lastName mappings

Add the required attribute mappings in Google Workspace

8

Turn on the SAML app for users

After the custom SAML app is created, open its Service status settings and turn the app on for the users, groups, or organizational units that should be allowed to sign in to CodeRabbit.The example below shows ON for everyone. Use the access scope that matches your rollout plan.
Google Admin Console service status screen with ON for everyone highlighted and organization names redacted

Turn on service access for the users who should sign in through Google Workspace

9

Test the SSO connection

In Test, click Open test URL and complete the Google Workspace sign-in flow with a user who has access to the custom SAML app and whose email matches your verified domain.Return to the account management SSO wizard and click Refresh logs until the latest test result shows Success. Do not activate SSO while the latest result is Pending or failed.
Account management SSO wizard showing the Open test URL button and a successful test result with user details redacted

Confirm the SSO test result succeeds before activation

10

Activate SSO

In Activate, review the activation message and click Activate SSO.
Activation changes sign-in behavior for the verified domain. After activation, users with that email domain must sign in to CodeRabbit through Google Workspace.
Account management SSO wizard with the Activate SSO button highlighted and the domain redacted

Activate SSO after the connection test succeeds

What’s next

Enterprise SSO overview

Return to the SSO overview to understand how Enterprise SSO fits into your CodeRabbit rollout.

Roles and permissions

Pair SSO with the right access controls by reviewing how roles work in your CodeRabbit organization.

Support

Contact CodeRabbit if the Security section is missing or the SSO test does not succeed.